Cisco ASA 5505 Configuration Manual page 1246

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring Active/Active Failover
create failover groups in the device manager. For both types of failover, you need to provide system-level
failover settings in the system context, and context-level failover settings in the individual security
contexts. For more information about configuring failover in general, see
About High
Seethe following topics for more information:
Failover > Setup Tab
Use this tab to enable failover on a adaptive security appliance in multiple context mode. You also
designate the failover link and the state link, if using Stateful Failover, on this tab.
Note
During a successful failover event on the adaptive security appliance, the interfaces are brought down,
roles are switched (IP addresses and MAC addresses are swapped), and the interfaces are brought up
again. However, the process is transparent to users. The adaptive security appliance does not send
link-down messages or system log messages to notify users that interfaces were taken down during
failover (or link-up messages for interfaces brought up by the failover process).
Fields
Note
Cisco ASA 5500 Series Configuration Guide using ASDM
60-10
Availability.".
Failover > Setup Tab
Failover > Criteria Tab
Failover > Active/Active Tab
Failover > MAC Addresses Tab
Enable Failover—Checking this check box enables failover and lets you configure a standby
adaptive security appliance.
The speed and duplex settings for an interface cannot be changed when Failover is enabled. To
change these settings for the failover interface, you must configure them in the Configuration >
Interfaces pane before enabling failover.
Use 32 hexadecimal character key—Check this check box to enter a hexadecimal value for the
encryption key in the Shared Key field. Uncheck this check box to enter an alphanumeric shared
secret in the Shared Key field.
Shared Key—Specifies the failover shared secret or key for encrypted and authenticated
communications between failover pairs.
If you checked the Use 32 hexadecimal character key check box, then enter a hexadecimal
encryption key. The key must be 32 hexadecimal characters (0-9, a-f).
If you cleared the Use 32 hexadecimal character key check box, then enter an alphanumeric shared
secret. The shared secret can be from 1 to 63 characters. Valid character are any combination of
numbers, letters, or punctuation. The shared secret is used to generate the encryption key.
LAN Failover—Contains the fields for configuring LAN Failover.
Interface—Specifies the interface used for failover communication. Failover requires a
dedicated interface, however, you can use the same interface for Stateful Failover.
Chapter 60
Configuring Active/Active Failover
Chapter 57, "Information
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents