Cisco ASA Failover - Multiple IPs on all interfaces

Posted on 2011-10-12
Last Modified: 2012-05-12
Hi All
Is there any advantage of having primary and standby ip addresses configured on inside,outside and DMZ interfaces when you are running ASA failover in Active/Standby mode.

ip address standby

Is there anyway to copy IPS (SSP-IPS40) configurations to standby fireawll automatically ?
Question by:tech2010
    LVL 36

    Expert Comment

    you can get away without standby addresses on the interfaces for normal operation, however you need to have at least management access to the standby for performing upgrades etc

    the IPS configuration is unfortunately not cluster aware and needs to be manually configured on both

    Author Comment

    Yes i know i can get away however is there any advantage of having multiple IP addresses on non-management interfaces i.e inside,outside and DMZ.
    LVL 5

    Expert Comment

    by:Feroz Ahmed

    You can have multiple interfaces on Inside,outside and DMZ Interfaces ,the procedure is as follows :

    ASA(Config-t)#int e0 for outside and multiple interfaces in int e0 is e0.1,e0.2,e0.3,e0.4 etc and in the similar way you can have multiple interfaces for inside and dmz network.

    Author Comment

    Thanks sm_feroz but I think your comment is not relevant to my question.
    LVL 5

    Accepted Solution


    Yes,Primary is State of Failover when once Context is configured and Failover is Up.There are 2 states in Failover Primary and Secondary when context is configured Primary and Secondary.
    When a Failover is being configured Context are created and these context can have inside,outside and Standby IP addressess and once when these context are configured successfully and the Failover state is UP ,then the status is shown as Primary as Active and Secondary as Standby.So,without configuring Inside,outside along with Standby one cannot create a Failover in ASA Firewall.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
    Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    25 Experts available now in Live!

    Get 1:1 Help Now