Cisco ASA Firewall Active / Standby Failover (2024)

The Cisco ASA firewall is often an important device in the network. We use it for (remote access) VPNs, NAT/PAT, filtering and more. Since it’s such an important device it’s a good idea to have a second ASA in case the first one fails.

The ASA supports active/standby failover which means one ASA becomes the active device, it handles everything while the backup ASA is the standby device. It doesn’t do anything unless the active ASA fails.

The failover mechanism is stateful which means that the active ASA sends all stateful connection information state to the standby ASA. This includes TCP/UDP states, NAT translation tables, ARP table, VPN information and more.

When the active ASA fails, the standby ASA will take over and since it has all connection information, your users won’t notice anything…

There are a number of requirements if you want to use failover:

  • Platform has to be the same: for example 2x ASA 5510 or 2x ASA 5520.
  • Hardware must be the same: same number and type of interfaces. Flash memory and RAM has to be the same.
  • Same operating mode: routed or transparent mode and single or multiple context mode.
  • License has to be the same..number of VPN peers, encryption supported, etc.
  • Correct license. Some of the “lower” models require the Security Plus license for failover (the ASA 5510 is an example).

In this lesson we’ll take a look how to configure active/standby failover. Here’s the topology I will use:

Cisco ASA Firewall Active / Standby Failover (1)

We have two ASA firewalls…ASA1 and ASA2. ASA1 will be the active firewall and ASA2 will be in standby mode. Their Ethernet 0/0 interfaces are connected to the “INSIDE” security zone while the Ethernet 0/1 interfaces are connected to the “OUTSIDE” security zone. The Ethernet 0/3 interface in the middle will be used to synchronize connection information for failover. R1 and R2 are only used so we can generate some traffic.

Configuration

We will start with the failover interface on ASA1. Make sure it’s not shut:

ASA1(config)# interface Ethernet 0/3ASA1(config-if)# no shutdown

And then we configure this ASA to be the active (primary) device:

ASA1(config)# failover lan unit primary

Now we will configure Ethernet 0/3 to be the failover interface:

Cisco ASA Firewall Active / Standby Failover (2024)
Top Articles
Creating an Active Directory Trust | itopia Help Center
Economy Statement by Eric Van Nostrand, Acting Assistant Secretary for Economic Policy, for the Treasury Borrowing Advisory Committee July 31, 2023
$4,500,000 - 645 Matanzas CT, Fort Myers Beach, FL, 33931, William Raveis Real Estate, Mortgage, and Insurance
855-392-7812
Did 9Anime Rebrand
Doublelist Paducah Ky
What Auto Parts Stores Are Open
Weapons Storehouse Nyt Crossword
123 Movies Black Adam
R Tiktoksweets
Oppenheimer Showtimes Near Cinemark Denton
The Murdoch succession drama kicks off this week. Here's everything you need to know
Uhcs Patient Wallet
Cpt 90677 Reimbursem*nt 2023
Ostateillustrated Com Message Boards
2 Corinthians 6 Nlt
Elemental Showtimes Near Cinemark Flint West 14
Forum Phun Extra
The Pretty Kitty Tanglewood
Account Suspended
Td Small Business Banking Login
Curver wasmanden kopen? | Lage prijs
Espn Horse Racing Results
Yog-Sothoth
Cain Toyota Vehicles
Discord Nuker Bot Invite
Foodsmart Jonesboro Ar Weekly Ad
Star Wars Armada Wikia
manhattan cars & trucks - by owner - craigslist
The Goonies Showtimes Near Marcus Rosemount Cinema
Log in to your MyChart account
Paradise Point Animal Hospital With Veterinarians On-The-Go
Insidious 5 Showtimes Near Cinemark Southland Center And Xd
Myra's Floral Princeton Wv
Current Time In Maryland
Dreamcargiveaways
24 slang words teens and Gen Zers are using in 2020, and what they really mean
Marie Peppers Chronic Care Management
Wisconsin Women's Volleyball Team Leaked Pictures
Sabrina Scharf Net Worth
Mid America Irish Dance Voy
Samantha Lyne Wikipedia
Lake Kingdom Moon 31
QVC hosts Carolyn Gracie, Dan Hughes among 400 laid off by network's parent company
Academic Calendar / Academics / Home
St Vrain Schoology
Amy Zais Obituary
Myra's Floral Princeton Wv
Advance Auto.parts Near Me
Rheumatoid Arthritis Statpearls
Mail2World Sign Up
March 2023 Wincalendar
Latest Posts
Article information

Author: Foster Heidenreich CPA

Last Updated:

Views: 6042

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Foster Heidenreich CPA

Birthday: 1995-01-14

Address: 55021 Usha Garden, North Larisa, DE 19209

Phone: +6812240846623

Job: Corporate Healthcare Strategist

Hobby: Singing, Listening to music, Rafting, LARPing, Gardening, Quilting, Rappelling

Introduction: My name is Foster Heidenreich CPA, I am a delightful, quaint, glorious, quaint, faithful, enchanting, fine person who loves writing and wants to share my knowledge and understanding with you.