Link to home
Start Free TrialLog in
Avatar of tech2010
tech2010

asked on

Cisco ASA Failover - Multiple IPs on all interfaces

Hi All
Is there any advantage of having primary and standby ip addresses configured on inside,outside and DMZ interfaces when you are running ASA failover in Active/Standby mode.

ip address 1.1.1.1 255.255.255.0 standby 1.1.1.2

Is there anyway to copy IPS (SSP-IPS40) configurations to standby fireawll automatically ?
Avatar of ArneLovius
ArneLovius
Flag of United Kingdom of Great Britain and Northern Ireland image

you can get away without standby addresses on the interfaces for normal operation, however you need to have at least management access to the standby for performing upgrades etc

the IPS configuration is unfortunately not cluster aware and needs to be manually configured on both
Avatar of tech2010
tech2010

ASKER

Yes i know i can get away however is there any advantage of having multiple IP addresses on non-management interfaces i.e inside,outside and DMZ.
Hi,

You can have multiple interfaces on Inside,outside and DMZ Interfaces ,the procedure is as follows :

ASA(Config-t)#int e0 for outside and multiple interfaces in int e0 is e0.1,e0.2,e0.3,e0.4 etc and in the similar way you can have multiple interfaces for inside and dmz network.
Thanks sm_feroz but I think your comment is not relevant to my question.
ASKER CERTIFIED SOLUTION
Avatar of Feroz Ahmed
Feroz Ahmed
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial