cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
433
Views
0
Helpful
3
Replies

Do I really need a stand by IP address on all my interfaces

cgicalgary
Level 1
Level 1

Do I have to have a standy by IP address bound to every interface. Right now some of my interfaces have stand by IP address assigned to them and some don't. It does not appear to make a diffrence on how the firewall performs. I understand you need a standby IP address if you plan to monitor both firewall nodes. But that would only be required on the managment interface. I have read the configuration guide and it states the stand by IP address must be in the same subnet. But it does not say if it is optional or not, Yet the ASDM allows you to configure the firewall in failover mode without a stand by IP address. I figure the ASDM would be enforcing the standby IP address requirement if it was a must. So what is the advantages/disadvantages

My best guess is:

The standby IP address is used to monitor the health of the interface. It is used for the PING test during the health check proccess.

1 Accepted Solution

Accepted Solutions

ddawson
Level 1
Level 1

Yes, you should have a standby address on every interface that's in use. As you've guessed, this address *is* used to monitor the health of the interface, so if you don't have it on some interfaces you don't really have full failover functionality.

View solution in original post

3 Replies 3

ddawson
Level 1
Level 1

Yes, you should have a standby address on every interface that's in use. As you've guessed, this address *is* used to monitor the health of the interface, so if you don't have it on some interfaces you don't really have full failover functionality.

That is what I thought, It just that I am under pressure to recover some IP address in a subnet so we can add more servers. Now I have a definite answer that I can give to the no more room response I am going to have to give

ajagadee
Cisco Employee
Cisco Employee

Below is the link to an excellent explanation by one of the netpros, I hope it helps.

http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Security&topic=Firewalling&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40^1%40%40.2cc1edc8/2#selected_message

Regards,

Arul

Review Cisco Networking products for a $25 gift card