Cisco Firewall :: Integrating Secondary Failover Unit ASA 5510?

Nov 20, 2011

I have a single production 5510 with 2 contexts.  Now I want to integrate the secondary failover unit. My question is: How much configuration needs to be done on the secondary firewall?  How much of the configuration will be sync'd from the primary to the secondary when the secondary is connected?
 
For example, do I need to add the following on the secondary or will it be sync'd from the primary?
 
admin-context NAME
context NAME
allocate-interface Ethernet0/0.14

[Code].....

View 3 Replies


ADVERTISEMENT

Cisco Firewall :: 5510 ASA Failover Pair For Access Second Unit Via VPN

Jun 11, 2009

we are running two failover pairs of asa (5510, 5505) in two different locations in active/standby configurations.Is it possible to access the inside ip of the standby unit via vpn terminated by the active unit? It's only for monitoring.With our configuration here it is not.Is that possible in general?

View 6 Replies View Related

Cisco Firewall :: 5520 - Procedure To Replace Failed Secondary ASA Unit

Apr 10, 2012

i just received a RMA for failed ASA 5520 that was acting as secondary unit in multicontext configuration. What would be correct procedure to install it back in production? Do i need to restore backed up config of the fallen unit or is it just enough to enable multimode and connect to existing (primary) unit? Any good link for documentation that deal with this issues.

View 5 Replies View Related

Cisco Firewall :: Rebuild ASA 5520 Failover Unit

May 12, 2011

What process I need to follow to rebuild my failover unit? I've had to turn it off because it seems that both the primary and secondary were thinking they should both be the active unit. I'm not sure why. But in turning off the failover, I had internet access again. So I think I want to rebuild the secondary unit's configuration. Do I need to turn off failover from the primary unit first? Disconnect the secondary unit, console into it and remove the configuration (command to remove from flash?)? Rebuild the interfaces..all interfaces or just STATE between the units? Just trying to get a list of the process

View 1 Replies View Related

Cisco Firewall :: ASA 5520 Failover Unit Anyconnect Licenses

Jan 2, 2012

So i setup a failover active / passive with 2 ASA5520's
 
Primary asa has 750 Anyconnect vpn licensing and the secondary asa has 2 Anyconnect licenses     
 
I haven't setup the second asa with the new 750 licenses i purchased but when i do a show version it shows that the failover licensed features shows 750...
 
Does this mean i do not have to install the secondary anyconnect licenses on the standby ASA unit?
 
output of secondary asa
:
Licensed features for this platform:Maximum Physical Interfaces       : Unlimited      perpetualMaximum VLANs                     : 150            perpetualInside Hosts                      : Unlimited      perpetualFailover                          : Active/Active 

[Code]......

View 1 Replies View Related

Cisco Firewall :: 5510 - ASA Dispatch Unit Percentage Increasing

Jan 25, 2012

I have just noticed that my Cisco ASA 5510 cpu utilization increasing upto 30-35 % and when i issue sh processes cpu-usage, i have found dispatch unit occupied most of utilization.

View 4 Replies View Related

Cisco Firewall :: Implement Secondary ISP To ASA 5510?

Aug 27, 2012

We are in the process of implementing secondary ISP to our ASA firewall and We would like to run both ISPs in parallel so we can test until we finally cutover?

View 2 Replies View Related

Cisco :: ASA 5520 - LU Allocate Xlate Failed / Failover Unit Reloads

Mar 24, 2010

We just had an issue with our failover unit reloading. In perusing the logs there were a number of %ASA-3-210007:
LU allocate x late failed, errors prior to the reload. These units had just had their OS upgraded to fix a DOS issue a few weeks ago. I have not seen the error since it reloaded. However, I was asked to report the issue just in case it is a bug in the new version of the OS.Two units in failover. 
 
Cisco Adaptive Security Appliance Software Version 8.0(5)9 Device Manager Version 6.0(2). Compiled on Mon 01-Feb-10 10:36 by buildersSystem image file is

"disk0:/asa805-9-k8.bin"Config file at boot was "startup-config"  
CP-ASA up 17 days 21 hoursfailover cluster up 17 days 22 hours
[code]....

View 1 Replies View Related

Cisco Firewall :: ASA 5510 ISP Failover

May 31, 2011

Configured ASA 5510 ISP failover and working fine.My ASA as configured as DHCP server also. So its serves IP addressing details including mask,default-gateway, DNS server IPs.Here my issue is whenever my ISP failover occurs my ASA sends previous ISP DNS server IPs to my inside clients.
 
Here i like to configure my ASA to serve IP addresses dynamically.Or is there any global DNS IP addresses which will work for all ISPs?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Failover With IP SLA Monitor?

Nov 28, 2011

Can I run Cisco ASA failover with dual ISP run active/standby configuration and SLA monitor to monitor the primary ISP gateway and failover to the secondary gateway but not failover to the failover firewall unless an actual event occurred that required a ASA failover?

View 3 Replies View Related

Cisco Firewall :: Configuring Failover For ASA 5510

Oct 16, 2012

I have two ASA 5510's that I want to setup in a Active/Standby configuration. My only question is on how to connect the inside ports to my LAN. I have 5 Catalyst 3750's stacked together that connect to the ASA's. Should I run the inside interface on ASA1 to a port on switch 1. Then run the inside interface on ASA2 to a port on switch2? And make sure both those ports are in the same VLAN? But, then when failover occured, how to I automatically make it clear the arp cache so the traffic starts flowing out of the right port?                   

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Failover Trunk

Nov 25, 2012

I have a customer with two ASA 5510s.  All four ports are used by the following interfaces: inside, outside, dmz, and failover.  This customer is looking at getting redundant internet connections, but we don't have any ports to the redundant connection.  What I'd like to know is it possible to configure sub interfaces on one of the currently occupied ports (I'm thinking inside) and use one for inside and one for failover.  This way I could have the other port free for the redundant internet connection.

View 1 Replies View Related

Cisco Firewall :: Failover Between ASA 5510 And 5520?

Sep 27, 2012

Cisco still doesn't provide failover (active/standby) between two different types of ASA, right?
 
[URL]
 
"The two units in a failover configuration must have the same hardware configuration. They must be the same model, have the same number and types of interfaces, and the same amount of RAM"

View 1 Replies View Related

Cisco Firewall :: ASA 5510 To Use Failover Possibilities

Jul 26, 2011

We are going to buy a new Firewall ASA5510 to use failover possibilities.I just need to be sure it will be possible to implement as I have the following output after a "show ver" command: Cisco Adaptive Security Appliance Software Version 8.3(1) [code]

As you can see the failover line is set as "Disabled perpetual".We are actually using base license as i have not been able to find any contact for CISCO to get official support or new license.

View 1 Replies View Related

Cisco Firewall :: 5510 ASA Failover Licensing?

Feb 28, 2011

I have a customer who has purchased a Cisco 5510 and after we received it and all the necessary VPN, 3DES etc. licensing for it, then informed us that they order 2 T1 lines so they can have Internet failover.
 
My question is: Does this require an additional specialized license from Cisco in order to enable and configure it?  And if so, what that part number is?

View 2 Replies View Related

Cisco Firewall :: How To Do Network Failover Between Two ASA 5510

Apr 16, 2011

How to design a network setup and achieve failover in the below scenario. 
 
                                                                                                    (Vendor router)
L3-Switch ---- ASA FW1 ---switch-- Router 1 ------ MPLS cloud1 ----- Router A ------------ L3 switch
                                                                                                     (Vendor router)
L3-Switch ---- ASA FW2 ---switch-- Router 2------ MPLS cloud2 ----- Router B------------ L3 switch
 
I am planning to achieve the failover either of the following ways -
 
1)  Configuring both ASA FW as active/standby method .

2) configuring ASA FW 1 tracking command pointing to the  ISP end ip address so the traffic would be moved to secondary firewall by putting a  AD as 1 on ASA FW ......pointing to the ISP ip address and other floating route ( with a higher AD value) to the secondary firewall interface.
 
3) To configure HSRP between the Routers.

View 2 Replies View Related

Cisco Firewall :: ASA 5510 - Configure HA Failover

Jun 8, 2013

I have 2 ASA5510-SSL50-K9, can I configure HA Failover ?

View 7 Replies View Related

Cisco Firewall :: ASA 5510 - License For Failover

Apr 19, 2011

I am looking for redundant asa deployment for fail over set up . however both units have csc cards. does  this product  ASA5510-CSC10-K9 has license for fail over ? what's the part no for asa failover license ?

View 2 Replies View Related

Cisco Firewall :: ASA 5510 Active And Standby Failover

Apr 18, 2012

i read that you need only one L-ASA5510-SEC-PL for setting up a Active/Standby Failover. I installed the license on the 1st ASA and tried to setup the failover via the ASDM wizard. It always fails, because the 2nd device can't have a 'base' license.So does this mean, i really need another license?

View 5 Replies View Related

Cisco Firewall :: 5510 Failover Hardware Compatibility

May 25, 2012

I have two ASA 5510, The one which I just got shows the CPU speed to be 1599MHz While the previous device (which is also 5510) reads the CPU as 1600 MHz.According to Cisco, for Failover redundant configuration, both devices must have same hardware configuration. Technically, this slight difference should not be an issue but I need to confirm that thess devices will work fine with failover configuration.

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - LAN Based Failover Not Working

Jun 23, 2011

I have ASA 5510 connected as shown in attached diagram.Ideally when ASA 1 is active and if I boot Switch-1, ASA-2 shood take over. But that is not happening.When I boot SW1 , ASA-2 shows "Failover LAN Interface: failover Ethernet0/0 (Failed - No Switchover)" and remains standby.Fail over works properly If ASA-1 boots.

View 7 Replies View Related

Cisco Firewall :: ASA 5510 Failover Subinterfaces Monitoring

Jan 30, 2013

i have a couple of ASA 5510 in Active/Failover configuration. Failover LAN is configured on management0/0 e the ASA are connected with a back-to-back direct cable.
 
ASA has an interface in access mode inside with standby ip address and show failover is compliant with expected result in show failover (Normal)
 
ASA-PRIMARY# sh failover Failover On Failover unit PrimaryFailover LAN Interface: LANfailover Management0/0 (up)Unit Poll frequency 1 seconds, holdtime 15 secondsInterface Poll frequency 5 seconds, holdtime 25 secondsInterface Policy

[Code]....

View 2 Replies View Related

Cisco Firewall :: Adding Failover To Active ASA 5510?

Oct 14, 2012

I am adding a failover asa to an a firewall that is already in production. They are both 5510's, they both have the same abount of ram, have the same code versions. Will there be any downtime while adding the secondary in?

View 2 Replies View Related

Cisco Firewall :: 5510 - Which License Needed For ISP Failover

Mar 3, 2011

I Have ASA 5510. And I had two ISPs and I need to configure ISP failover. So which license i need? I Had License ASA-CSC10-PLUS License.

View 1 Replies View Related

Cisco Firewall :: 5510 / Setup Snmpv3 With Active Failover?

Apr 1, 2012

What I am attempting to do is setup snmpv3 on two failover 5510's .The problem I am running into, the snmp management software rejects one of the devices as it sees it as having a duplicate engine ID since the two devices share the same config.  Would like to know how this would work in an active/active setup being able to poll both devices.

View 2 Replies View Related

Cisco Firewall :: Can Two ASA 5510 With Different Modules Be In Active Failover Design

Oct 23, 2012

understanding clear about new Cisco ASA 5515-x, 5525-x.I know that this device supports IPS which is included to this appliance without any additional modules.But can this box support IPS and content-filering (Cisco ASA CX or so..) in the same time.
 
 The problem also in next. Can two ASA 5510 with diffrent modules (in one AIP-SSM and in other CSC-SSM) be in active/active failover design?

View 3 Replies View Related

Cisco Firewall :: ASA 5510 Switch Failover License From Old To New Device

Nov 1, 2011

I used to have this situation where I need to replace faulty ASA5510 (this FW did not failover to standby FW) with the new one.
 
But the problem is the new ASA5510 came with Base License only not with Security Plus License which is needed to allow this brand new device to be configure failover.
 
how do I pull out Security Plus License from old FW and switch it to new FW (Base License) and activate to Security Plus License.

View 5 Replies View Related

Cisco Firewall :: 5510 Active / Standby Failover Errors

Jan 25, 2012

I just added a new 5510 failover unit to an existing 5510 and when connecting my new outside interface on an Active/Standby firewall pair, i get errors messages (red x) on each port scan (monitor & syslog) although the error message indicate all ports are good...additionally the firewalls flip between active and standby non stop. I remove the new standby unit outside interface from a shared switch and everything clears up.

View 1 Replies View Related

Cisco Firewall :: 5510 Setup In Active / Standby Failover Configuration

May 8, 2012

We have 2 ASA 5510's setup in an active, standby failover configuration. When the primary fails over to standby, the 3rd party cert does not failover to the standby ASA. The users then receive the CERT missing, invalid message and have to select yes, no to move on. This does not occur when the primary is not in failover mode. It is my understanding that failover fails over certs but in our case it does not apper to be working correctly.

View 1 Replies View Related

Cisco Firewall :: How To Design ASA 5510 Failover For Process Control Network

Mar 19, 2013

I'm currently working on setting up 2 ASA 5510's with redundancy/failover. I'm not an expert when it comes to the ASA's so I'm not 100% sure if I can do what I need to.I have 2 inside networks that need to remain separate, a DMZ network,and an outside network. Since each network connects via ethernet to one of the 4 ethernet ports on the ASA 5510's, all 4 ethernet ports on the ASA 5510 will be in use. If I wanted to setup one firewall as Active and the other as standby, how would I go about doing that? Do I need a direct ethernet connection between the 2 firewalls to use something such as HSRP? Or would the Standby firewall be able to tell if the Active firewall is OK since they would both be connected on each of their interfaces to the same networks?        

View 1 Replies View Related

Cisco Firewall :: Adding Failover ASA 5510 Back After Configuration Changes On Primary

Nov 28, 2012

I had a working active/passive pair of ASA5510's, and then I had to do a rush firmware upgrade, but didn't have time to do it on the secondary at the same time.  Now I have made config changes and upgraded the secondary firmware to be the same, and wish to know if I plug it back in if it will think the secondary has the "correct" config or if it will know that the primary is newer.  I disconnected the failover cable because it was complaining about version mismatches constantly.
 
Is it safe to add the secondary back in or is it possible it will be declared newer and overwrite the config?

View 6 Replies View Related

Cisco Firewall :: PIX 515E / ASA 5510 Heartbeat Failover (Direct Connection)

Apr 2, 2011

Currently, my customer has 2 units of Cisco PIX 515E running on Active/Standby mode. As for the heartbeat link, there are 2 dedicated switches placed in between both the Cisco PIX 515E i.e. FW1 --> SW1 --> SW2 --> FW2.

My customer will be changing both the Cisco PIX 515E to Cisco ASA 5510. Now, they are asking me, since they will be using Cisco ASA 5510 eventually, can the heartbeat link be a direct UTP cross cable or must the 2 switches in between still exist?

I remember I have tested this before, few years back, in the event I were to pull out the UTP cross cable that's connecting both the Cisco ASA 5510 Firewalls directly (without any switches in between), the Active/Standby mode still works fine. It doesn't go bad whereby both the Cisco ASA 5510 suddenly becomes Active/Active, and causes network issue.

Are switches required for the heartbeat link in a Cisco ASA environment or can a direct UTP cross cable connection be adequate.

View 3 Replies View Related

Cisco Firewall :: 5510 Recommended Port-security Settings For ASA HA Failover

Dec 28, 2011

I have a pair of ASA 5510s configured in active/standby mode. I have already configured the fail over settings on the firewalls. Both firewalls are connected to a 2960G. I made a change to the interfaces on the 2960 to allow 2 mac addresses on each port. [code]

Upon testing failover via the failover active command, I get port-security errors on the outside interface for each device:%PORT_SECURITY-2- PSECURE_ VIOLATION: Security violation occurred, caused by MAC address aaaa.bbbb.cccc on port GigabitEthernet0/8. After a few minutes, the error goes away and I can then connect to each firewall. It seems that it still waits for the aging time to expire before allowing the other MAC address. Shouldn't the "maximum 2" setting allow for both mac addresses?
 
I'd rather not have to hardcode the firewall's MAC addresses on each switchport because I could see this causing problems for us down the road. Is there anything else that can be done?

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved