We have configured ASA Active standby failover with ASA5505 . When primary unit power off, secondary unit became active. when primary unit power on, then primary unit is becoming active again. i think for active standby setup there is no preemption. The real issue is when primary ASA became active after power on all the external connectivity getting down. Please see the below config,
ftp mode passive clock timezone AST 3 access-list inside_access_in extended permit icmp any any access-list inside_access_in extended permit ip any any access-list inside_access_in extended permit ip any host MPLS_Router access-list outside_access_in extended permit icmp any any access-list outside_access_in extended permit ip any any access-list outside_access_in extended permit ip any 192.168.2.0 255.255.255.0 pager lines 24 logging enable logging asdm informational mtu inside 1500 mtu outside 1500 failover failover lan unit primary failover lan interface FAILOVER Vlan3 failover key ***** failover interface ip FAILOVER 10.1.1.1 255.255.255.0 standby 10.1.1.2
When we power on primary unit, secondary unit moving to standby.
We cannot ping to our internet router. The strange things which we noticed that we can ping to 192.168.3.9(Standby ASA), we cannot ping to 192.168.3.8(Primary ASA) when primary ASA power on and become active.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...