Professional Documents
Culture Documents
CCIE
Introduction: CCIE
ASA Failover
ASA Active/Standby Failover
It is a redundancy feature of ASA firewall. For the failover configuration we need two exactly the same ASA connected each other through a
dedicated failover link. There are few requirements for this failover:-
1. Stateless(regular) Failover
2. Stateful Failover
All the failover information for each connection information is passed to failover
End user no need to reconnect
State data include global data pool information or states, connection, translation, PAT etc is passed.
Provided by lan base failover
Whenever failover occurs the following stateful information are passed to standby unit,
1. DHCP client
2. PPPoE (Point to point protocol over Ethernet)
3. IPv6
There are basically two types of failover configuration, Active/Active and Active/Standby failover. The difference between them is that in
active/active failover must run on multiple context mode and both ASA can run traffic (C1 is ASA1 and C2 in ASA2).In active/standby
failover only one ASA pass traffic while other waits in standby state. Both failover configuration support stateful or stateless failover.
Note: - Failover hello messages are generated on the failover link in every 15 seconds by default.