cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
529
Views
5
Helpful
5
Replies

How do I use Cisco MARS to monitor two ASA (active/stby) with IPS modules?

zhichao
Level 1
Level 1

Hi

The two ASA with IPS modules are in active/standby mode. When I try to add both the two IP (active/standby) into the MARS, the MARS will complain duplicated hostnames.

How to setup MARS to monitor ASA with IPS with active standby topology?

Thanks!

1 Accepted Solution

Accepted Solutions

andrew.burns
Level 7
Level 7

Hi,

The fundamental problem with this scenario is that you have non-failover capable modules in a failover chassis - think of the ASA failover pair as one device and the IPS modules as two completely separate devices.

Then, as already mentioned, add only the primary ASA. (The secondary will never be passing traffic in standby mode so it's not actually needed in MARS) Then, with the first IPS module you can add it as a module of the ASA or as a standalone device (MARS doesn't care). With the second IPS module the only option is to add it as a separate device anyway.

In a failover scenario the ASA's swap IP's but the IPS's don't so whereas you'll only ever get messages from the active ASA you'll get messages from both IPS IP's depending on which one happens to be in the active ASA at the time.

Don't forget that you have to manually replicate all IPS configuration every time you make a change.

HTH

Andrew.

View solution in original post

5 Replies 5

Fernando_Meza
Level 7
Level 7

Hi ...I don't think you can add them both. As you have a failover configuration then only one IP ( the active ) is the one you need to bring reports from. I suggest you to configure the Management IP address for the ASAs and add the active one only. Using the discovery option you should be able to add the IPS module as well once the ASA has been added.

rfladischer
Level 1
Level 1

you must add the asa with the primary ip address and then add both ips modules (with different ip addr. and different hostnames).

Hi

You mean both the two IPS as the modules to the same ASA IP?

Thanks!

a.kiprawih
Level 7
Level 7

andrew.burns
Level 7
Level 7

Hi,

The fundamental problem with this scenario is that you have non-failover capable modules in a failover chassis - think of the ASA failover pair as one device and the IPS modules as two completely separate devices.

Then, as already mentioned, add only the primary ASA. (The secondary will never be passing traffic in standby mode so it's not actually needed in MARS) Then, with the first IPS module you can add it as a module of the ASA or as a standalone device (MARS doesn't care). With the second IPS module the only option is to add it as a separate device anyway.

In a failover scenario the ASA's swap IP's but the IPS's don't so whereas you'll only ever get messages from the active ASA you'll get messages from both IPS IP's depending on which one happens to be in the active ASA at the time.

Don't forget that you have to manually replicate all IPS configuration every time you make a change.

HTH

Andrew.

Review Cisco Networking products for a $25 gift card