Solved

Does Cisco ASA 5505 active/standby require standby ip address on all interfaces?

Posted on 2013-10-23
2
575 Views
Last Modified: 2013-10-23
We have a pair of ASA 5505 firewalls configured in active/standby mode, with five interfaces / vlans / subnets configured, some with private IP ranges, some public.  It all works.

Business requirements are dictating that we split some of our subnets into smaller pieces to isolate certain applications from others.  All the instructions I find re: active/standby configurations say to specify a standby IP address on all interfaces other than the failover link.

When dealing with, say, /28 subnets, chewing up two of the addresses for the firewalls can start being a significant percentage of the available addresses in that subnet.

Is it really necessary to add a standby IP address for all interfaces, or could we get by with doing so on just the interfaces through which we're likely to connect to the management interface?
0
Comment
Question by:TerryMott
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 7

Accepted Solution

by:
tolinrome earned 500 total points
ID: 39594512
0
 

Author Closing Comment

by:TerryMott
ID: 39595445
Great! Thanks.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Can't access Internet behind Cisco Router 14 54
Cisco ASA 5506 5 80
ASA - RV130 VPN tunnel, cannot pass traffic 8 84
What is an ASP Table on a Cisco ASA? 3 51
In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question