• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 628
  • Last Modified:

Cisco ASA Failover - Multiple IPs on all interfaces

Hi All
Is there any advantage of having primary and standby ip addresses configured on inside,outside and DMZ interfaces when you are running ASA failover in Active/Standby mode.

ip address 1.1.1.1 255.255.255.0 standby 1.1.1.2

Is there anyway to copy IPS (SSP-IPS40) configurations to standby fireawll automatically ?
0
tech2010
Asked:
tech2010
  • 2
  • 2
1 Solution
 
ArneLoviusCommented:
you can get away without standby addresses on the interfaces for normal operation, however you need to have at least management access to the standby for performing upgrades etc

the IPS configuration is unfortunately not cluster aware and needs to be manually configured on both
0
 
tech2010Author Commented:
Yes i know i can get away however is there any advantage of having multiple IP addresses on non-management interfaces i.e inside,outside and DMZ.
0
 
Feroz AhmedSenior Network EngineerCommented:
Hi,

You can have multiple interfaces on Inside,outside and DMZ Interfaces ,the procedure is as follows :

ASA(Config-t)#int e0 for outside and multiple interfaces in int e0 is e0.1,e0.2,e0.3,e0.4 etc and in the similar way you can have multiple interfaces for inside and dmz network.
0
 
tech2010Author Commented:
Thanks sm_feroz but I think your comment is not relevant to my question.
0
 
Feroz AhmedSenior Network EngineerCommented:
Hi,

Yes,Primary is State of Failover when once Context is configured and Failover is Up.There are 2 states in Failover Primary and Secondary when context is configured Primary and Secondary.
When a Failover is being configured Context are created and these context can have inside,outside and Standby IP addressess and once when these context are configured successfully and the Failover state is UP ,then the status is shown as Primary as Active and Secondary as Standby.So,without configuring Inside,outside along with Standby one cannot create a Failover in ASA Firewall.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now