cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
386
Views
0
Helpful
3
Replies

VPN Clustering

johng231
Level 3
Level 3

Hello Everyone,

We're planning on purchasing 2 ASA5510-SEC-BUN-k9 for replacing a VPN 3005 concentrator and a PIX 515E firewall.

We want to have the 2 ASA(s) in active/standby failover and enable the VPN cluster for remote VPN access only. Is this possible to perform?

Thanks in advance !

John

1 Accepted Solution

Accepted Solutions

John,

Only active unit in failover can participate in VPN load balancing.

So you cannot have load balancing and failover running on same two boxes.

That limitation has not been lifted so far, (speculation begins) mostly because of the implementation of failover, where stateful updates go from one (active) box to the other (standby) and not both ways as would be required in failover-load-balancing scenario(speculation ends)

Marcin

View solution in original post

3 Replies 3

Marcin Latosiewicz
Cisco Employee
Cisco Employee

John,

What do you mean by cluster?

Two ASAs can either be in failover or be in load balancing cluster (or form a failover and being in that state become part of VPN load lanacing cluster with third ASA).

In either of the scenarios: yes the ASA will be able to terminate RA only (noth IPsec and SVC), clientless access is also considered remote access.

It's quite standard and widely deployed scenario en par (and better) with vpn3k and PIXes

Marcin

well I want to have redundancy on the ASA(s) so I plan on setting it up in active/standby failover, I also want to use the VPN cluster feature to loadbalance remote IPSEC connections between both devices instead of one just sitting there cold. Can you have this type of design ?

John,

Only active unit in failover can participate in VPN load balancing.

So you cannot have load balancing and failover running on same two boxes.

That limitation has not been lifted so far, (speculation begins) mostly because of the implementation of failover, where stateful updates go from one (active) box to the other (standby) and not both ways as would be required in failover-load-balancing scenario(speculation ends)

Marcin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card