cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
685
Views
0
Helpful
7
Replies

Configuring Active/Standby Failover on an ASA 5520

browningm
Level 1
Level 1

When setting up the Stateful failover link, are there any issues if you use the management interface or should you only use an ethernet interface?

7 Replies 7

vitripat
Level 7
Level 7

You can use the management interface for stateful failover. However, if you are using gigabit data interfaces, its recommended that stateful link also be a gigabit interface.

Ok thanks.

Then next question will be that I'm having some issues trying to enable the failover. I have gone through the configurations and made sure have that everything is correct. I've checked to make sure that they are both on same version, mode.

After I enter command for failover, nothing happens...are there any suggestions that could give that I might be overlooking?

You need to enter failover command on both Primary and Secondary box to get failover working. Please refer to flollowing link also to make sure that configuration has been done as defined here:

http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/general/failover.htm#wp1058096

Sorry should have been more clear on that part. I have done the failover command on the primary first and the secondary afterward with no luck.

Also just saw this and not sure if might be an issue but when do sh ver on both, the primary hardware is ASA5520 and secondary is ASA5520-k8. Will this be an issue?

What version are you running? Were you trying to configure failover from ASDM wizard? If yes, it wont recognize them as same hardware due to a bug, you need to configure failover from CLI. If you did configure it from CLI, there shouldnt be any issue. Can you provide the configuration from the Primary firewall?

I believe I just found what might be causing the issue. The primary ASA has different WebVPN license than the secondary ASA.

ok .. if that is the case, failover will not work as it needs same license on both devices.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card