Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

ASA5525 : Configure Active/Active

Hi All,

I'm trying to configure Active/Active in 2 new ASA5525 using the Wizard. Just to begin, both ASA5525 G0/3 is connected to a dumb switch and configured with LAN IP 10.1.1.1/24 & 10.1.1.2/24 respectively. ASDM has been enabled on that LAN interface and both unit can reach each other.

When I tried to use the HA Wizard, it failed at Step 2 of 7, as shown in the attached screenshot.

Appreciate your kind advise on this. What other initial configurations need to be done?

Thank you.

-----

Regards,

Danny

  • Firewalling
Everyone's tags (3)
4 REPLIES
Hall of Fame Super Silver

ASA5525 : Configure Active/Active

Can the PC you are running ASDM on reach the peer firewall directly (apart from the HA wizard process) at 172.16.1.2?

If not, and that IP is otherwise reachable, we often see new out of the box ASA 5500-X series needing to have strong encryption enabled.

Check "show version" for 3DES-AES key activation and also set "ssl encryption aes256-sha1" for ASDM to work properly.

ASA5525 : Configure Active/Active

Hi Marvin,

From my PC, I can reach both firewall and connect via ASDM directly. So, you're saying I need to add 'ssl encryption aes256-sha1' for the ASDM peer testing to work properly? Cause for my PC to connect to firewall ASDM, I've changed the encryption to rc4-sha1. So, will it be best if I enable all the encryption?

Hall of Fame Super Silver

ASA5525 : Configure Active/Active

Well if your PC can reach the secondary firewall with ASDM, that should be OK encryption-wise.

Can you confirm you are able to use 172.16.1.2 for its reachability? Can the priamary firewall (172.16.1.1 I assume) also reach that address (ping)?

ASA5525 : Configure Active/Active

Hi Marvin,

Yes, primary firewall can reach secondary firewall via ping. I've also tested the HA setup using CLI and is working fine. Just want to solve the problem why wizard is not working.

Anyway, before starting the wizard, I only connect port 1 of primary firewall to port 1 of secondary firewall. Configure an IP and both able to ping to each other. Then, I just connect to ASDM via management port of primary firewall to start the wizard.

Is this correct?

286
Views
0
Helpful
4
Replies
This widget could not be displayed.