Solved

Cisco ASA 5520 question ?

Posted on 2009-04-01
9
624 Views
Last Modified: 2012-05-06
Hi Experts


I have 2 cisco asa 5520, does cisco ASA 5520 have other method that could do redundancy beside HSRP ? if it does, what is the name of that method ? and how to set it up with 2 x cisco asa 5520 ? Thanks.
0
Comment
Question by:SJCA
  • 5
  • 4
9 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24040150
Actually, they don't do HSRP.  The preferred method is to use the two in a failover pair.  The primary IP address floats between the two ASA's depending on which is active.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml
0
 
LVL 1

Author Comment

by:SJCA
ID: 24040244
So only cisco router/switch do HSRP ?

Thanks.
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24040301
Correct.  HSRP is an IOS feature.
0
 
LVL 1

Author Comment

by:SJCA
ID: 24040696
Hi there,

Sorry I'm new to ASA, just last few questions:
what is single or multiple context mode ? How do we know if it's single or multiple context mode? Can we change from single to multiple context mode or vice versa from ASA ? and How do we do that ?

Thanks.

"Active/Standby Failover is available on units that run in either single or multiple context mode"
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 43

Expert Comment

by:JFrederick29
ID: 24040726
Multiple context mode lets you virtualize the Firewall meaning you could have contextA for customerA and contextB for customerB.  It would appear as if you "virtually" have two firewalls.  Stick with single context mode if you don't need the features multiple context mode provides as it is simpler.
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24040811
By the way, the Firewalls come with two customer contexts and 1 admin context.  If you wanted more, you would need to buy additional licenses.

Here is a good overview of contexts:

http://www.ciscopress.com/articles/article.asp?p=426641
0
 
LVL 1

Author Comment

by:SJCA
ID: 24052390
Hi there,

Last question, my firewall is now showing Failover: Active/Active, how do i change it to Active/Standby ? I'd like to go with the method active/standby for my pair of firewall. Thanks.
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 24052439
Active/Active just allows you to do both, i.e. if it showed active/standby, you aren't licensed to do active/active.  In other words, you are fine to do active/standby.
0
 
LVL 1

Author Comment

by:SJCA
ID: 24052542
Thanks a lot.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now