Configuring Failover; Failover Configuration Limitations; Configuring Active/Standby Failover - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Chapter 14

Configuring Failover

Table 14-6
ASA 5500 series adaptive security appliance failover times.
Failover Condition
Active unit loses power or stops normal operation.
Active unit main board interface link down.
Active unit 4GE card interface link down.
Active unit IPS or CSC card fails.
Active unit interface up, but connection problem
causes interface testing.
Configuring Failover
This section describes how to configure failover and includes the following topics:

Failover Configuration Limitations

You cannot configure failover with the following type of IP addresses:
Additionally, the following restrictions apply:

Configuring Active/Standby Failover

This section provides step-by-step procedures for configuring Active/Standby failover. This section
includes the following topics:
OL-12172-03
Failover Configuration Limitations, page 14-19
Configuring Active/Standby Failover, page 14-19
Configuring Active/Active Failover, page 14-27
Configuring Unit Health Monitoring, page 14-39
Configuring Failover Communication Authentication/Encryption, page 14-39
Verifying the Failover Configuration, page 14-40
IP addresses obtained through DHCP
IP addresses obtained through PPPoE
IPv6 addresses
Stateful Failover is not supported on the ASA 5505 adaptive security appliance.
Active/Active failover is not supported on the ASA 5505 adaptive security appliance.
You cannot configure failover when Easy VPN remote is enabled on the ASA 5505 adaptive security
appliance.
VPN failover is not supported in multiple context mode.
CA server is not supported. If you have a CA server configured on the active unit, the CA server
functionality will be lost when the unit fails over. The crypto ca server command and associated
commands are not synchronized or replicated to the peer unit.
Minimum
Default
800 milliseconds
15 seconds
500 milliseconds
5 seconds
2 seconds
5 seconds
2 seconds
2 seconds
5 seconds
25 seconds
Cisco Security Appliance Command Line Configuration Guide
Configuring Failover
Maximum
45 seconds
15 seconds
15 seconds
2 seconds
75 seconds
14-19

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents