cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
599
Views
9
Helpful
4
Replies

IPS + Failover?

jt3rry
Level 1
Level 1

Hello, I'm researching the ASA platform I'm interested in Active/Active & Active/Standby configurations. I've not found any documentation (or configuration options) that would allow the IPS module to take part in the failover or loadbalance process. In other words, if I were to run two ASA's in a failover mode (either A/A or A/S) it apears each IPS module would need to be maintained separately, can anyone help me verify this?

Thanks!

4 Replies 4

vitripat
Level 7
Level 7

That is true. Currently both the SSM modules have to be maintained separately. Unlike in ASA where configuration is replicated from Active to Standby ASA, there is no such concept in SSM modules.

We need to make sure that both SSM modules have exactly same configuration. Now depending on the active ASA, SSM module in the respective ASA will be inspecting the traffic.

Hope this clears things.

Regards,

Vibhor.

I'd like to ask a follow-up question. Suppose, I have two ASA's in HA mode (Active-Standby) each with an IDS SSM module.

Does the health of the SSM module have any affect on the HA status of the ASA's?

In other words, if the SSM module in the Active ASA fails, will there be a failover to the Standby? My guy tells me NO but I'd like to confirm with folks in the forum. Thank you.

Yes. If SSM module fails, your Active PIX will also failover to the Standby PIX. When this happens, following debug message is logged if debugs are enabled-

fover_health_monitoring_thread: Primary: Switching to FAILED for reason Detect service

card failure.

Hope this helps.

Regards,

Vibhor.

I was able to so some testing today, and in "inline fail-close" mode the reset of just the IPS module (not the ASA) will initiate the failover of the whole ASA. Might be a handy for upgrades mid-day, but then again there's always inline fail-open mode for that

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card