ASA Active/Active Question

Unanswered Question
Apr 9th, 2007
User Badges:

My question goes into the VPN world. I've read when in active/active config the ASA's do not support vpn/ipsec tunnel failover. My question is does it support IPSEC/VPN's at all in active/active? I mean i realize they may not failover but if I don't care if they are down can i terminate them to 1 or is it just not possible to use VPN/IPSEC with an ASA active/active setup? Hope this helps.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
sebastan_bach Mon, 04/09/2007 - 06:23
User Badges:

hi sorry vpn cannot be configured on the active/active setup. it does not support for vpns on failover setup u need to configure active/standy.



netsec123 Fri, 08/10/2007 - 20:26
User Badges:

Hi Guys,

In active / standby mode, would I use the track command to set up the 2nd [failover] vpn tunnel? I'm assuming the 2nd ISP would plug into another VLAN port on the ASA and once tracking failed, a new tunnel would be negotiated. Yes?

ddidier Wed, 08/22/2007 - 06:17
User Badges:

I believe that version 8.x of the ASA supports Active/Active VPN failover. I looked quickly and couldn't find the notes on this, but I know that this is something I asked about in the past and was told 8.x will support this.



This Discussion