cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
732
Views
0
Helpful
2
Replies

ASA and vpn load balancing

eric.loiseau
Level 1
Level 1

Hi,

I am configuring 2 ASA5540 for internet trafic inside to outside ,

outside to inside (web,smtp) but also vpn load balancing for client to site , site to site and webvpn.

In the doc I can configure them for internet trafic as Active/Standby or Active/active.

for vpn : I can use vpn load balancing

But no information if I want to use the active/passif and vpn load balancing together.

Any thoughts on which way to go? what is the best thing to do ?

Regards

2 Replies 2

brispin
Level 1
Level 1

I think it is better to use Active/Active for VPN load balancing because in such a config both of the devices can share the load among themselves as compared to Active/standby.

Hi,

I think that you cannot use an Active/Active configuration for VPN connections as it is stated on Cisco's documentation: "Note: VPN failover is not supported on units that run in multiple context mode as VPN is not supported in multiple context. VPN failover is available only for Active/Standby Failover configurations in single context configurations" available at http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml

Hope it helps