Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Active/Active or Active/Standby


What is practically advantage of Active/Active ? if i do Active/Standby then any problem in my network ?

What is best practise ? please share.




Active/Active or Active/Standby

As you already know, Cisco ASA supports two failover configurations, Active/Active Failover and Active/Standby Failover. Each failover configuration has its own method to determine and perform failover. With Active/Active Failover, both units can pass network traffic. This lets you configure "somewhat" load balancing on your network. Active/Active Failover is only available on units that runs in multiple context mode. With Active/Standby Failover, only one unit passes traffic while the other unit waits in a standby state. Active/Standby Failover is available on units that run in either single or multiple context mode. Both failover configurations support stateful or stateless (regular) failover.

Note: Dynamic routing and VPN failover, are amoung the few features, that is not supported on units that runs in multiple context mode.

Conclusion: If you don't need to enable Dynamic routing and VPN in your FW, go for ACTIVE/ACTIVE. This is Cisco's best practise.

P/S: If you think this comment is useful, please do rate them nicely :-)

Warm regards, Ramraj Sivagnanam Sivajanam Technical Specialist/Service Delivery Manager – Managed Service Department

Active/Active or Active/Standby

Hi Biplobkhan,

If you want to load balance your traffic to some extent then you can go for the Active-Active scenario where your ASA should be in multicontext mode. Lets say one context will have ASA1 as the primary and ASA2 as the secondary. The other context will have ASA2 as the primary and ASA1 as the secondary. So both the devices will take the traffic for different contexts and acts as a failover for the respective contexts.

Active/Standby will have always one device as the primary and another as the secondary. If primary(Active firewall) fails then the secondary becomes active.

So its up to you how you chose for your scenario.

Please do rate if the given information helps.



Active/Active or Active/Standby


To quote from the confiuration guide,

"The type of failover you choose depends upon your ASA configuration and how you plan to use the ASAs."

For example if you have a pair of ASA terminating your Internet and VPN connectivity then choose Active/Standby.

See below a guide for Active/Active

Active/Standby guide

New Member

Active/Active or Active/Standby


Thanks everyone for sharing of your strong exprience and Knowledge.



Active/Active or Active/Standby

Hi Bro

If you think the comments provided is helpful, please do rate them nicely :-) and mark this question as ANSWERED, so that the others too could learn from our experience.

Warm regards, Ramraj Sivagnanam Sivajanam Technical Specialist/Service Delivery Manager – Managed Service Department
CreatePlease login to create content