Cisco ASA 5505 Configuration Manual page 1204

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Failover Feature/Platform Matrix
If an interface has only IPv6 addresses configured on it, then the adaptive security appliance uses IPv6
neighbor discovery instead of ARP to perform the health monitoring tests. For the broadcast ping test,
the adaptive security appliance uses the IPv6 all nodes address (FE02::1).
If all network tests fail for an interface, but this interface on the other unit continues to successfully pass
traffic, then the interface is considered to be failed. If the threshold for failed interfaces is met, then a
failover occurs. If the other unit interface also fails all the network tests, then both interfaces go into the
"Unknown" state and do not count towards the failover limit.
An interface becomes operational again if it receives any traffic. A failed adaptive security appliance
returns to standby mode if the interface failure threshold is no longer met.
If a failed unit does not recover and you believe it should not be failed, you can reset the state by entering
Note
the failover reset command. If the failover condition persists, however, the unit will fail again.
Failover Feature/Platform Matrix
Table 57-3
Table 57-3
Failover Feature Support by Platform
Platform
Cisco ASA 5505 adaptive security appliance
Cisco ASA 5500 series adaptive security appliance
(other than the ASA 5505)
Failover Times by Platform
Table 57-4
adaptive security appliance.
Table 57-4
Cisco ASA 5500 Series Adaptive Security Appliance Failover Times
Failover Condition
Active unit loses power or stops normal operation.
Active unit main board interface link down.
Active unit 4GE card interface link down.
Active unit IPS or CSC card fails.
Active unit interface up, but connection problem
causes interface testing.
Cisco ASA 5500 Series Configuration Guide using ASDM
57-12
shows the failover features supported by each hardware platform.
LAN-Based
Failover
Yes
Yes
shows the minimum, default, and maximum failover times for the Cisco ASA 5500 series
Minimum
800 milliseconds
500 milliseconds
2 seconds
2 seconds
5 seconds
Chapter 57
Information About High Availability
Stateful
Active/Standby
Failover
Failover
No
Yes
Yes
Yes
Default
15 seconds
5 seconds
5 seconds
2 seconds
25 seconds
Active/Active
Failover
No
Yes
Maximum
45 seconds
15 seconds
15 seconds
2 seconds
75 seconds
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents