cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
284
Views
0
Helpful
1
Replies

ASA/Pix 7.X Failover addressing

jeffasher
Level 1
Level 1

In 6.X standby IP addressing was not mandatory for the interface configurations. Has this been changed in 7.X? My coworkers encountered problems configuring failover on a public network where we only had a slash 30 address space. Is there any way to configure failover on an ASA in this scenario?

1 Reply 1

Fernando_Meza
Level 7
Level 7

I had similar issue on PIX6.3 .. unfortunately I think you need to specify an ip address for the failover on version 7.0 A work around will be to use a router at the edge instead:

1.- Configure the router external interface using the current IP address allocated to the ASA's outside interface. The dafault gateway for the router will be the ISP router.

2.- Create a small segment i.e /29 and allocate the ip addresses accordingly to both ASA's outside and Internal interface on the edge router. The ASA's default gateway will be the IP address allocated to the inside interface of the router.

3.- Reconfigure failover accordingly.

4.- Check Nat, statics, PAT etc ..

The other option of course is to get a /29 public range

I hope it helps .. please rate it if it does !!

Review Cisco Networking products for a $25 gift card