14-19
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Configuring Failover
Configuring Failover
This section describes how to configure failover and includes the following topics:
•
Failover Configuration Limitations, page 14-19
•
Configuring Active/Standby Failover, page 14-19
•
Configuring Active/Active Failover, page 14-27
•
Configuring Unit Health Monitoring, page 14-39
•
Configuring Failover Communication Authentication/Encryption, page 14-39
•
Verifying the Failover Configuration, page 14-40
Failover Configuration Limitations
You cannot configure failover with the following type of IP addresses:
•
IP addresses obtained through DHCP
•
IP addresses obtained through PPPoE
•
IPv6 addresses
Additionally, the following restrictions apply:
•
Stateful Failover is not supported on the ASA 5505 adaptive security appliance.
•
Active/Active failover is not supported on the ASA 5505 adaptive security appliance.
•
You cannot configure failover when Easy VPN remote is enabled on the ASA 5505 adaptive security
appliance.
•
VPN failover is not supported in multiple context mode.
•
CA server is not supported. If you have a CA server configured on the active unit, the CA server
functionality will be lost when the unit fails over. The
crypto ca server
command and associated
commands are not synchronized or replicated to the peer unit.
Configuring Active/Standby Failover
This section provides step-by-step procedures for configuring Active/Standby failover. This section
includes the following topics:
Table 14-6
ASA 5500 series adaptive security appliance failover times.
Failover Condition
Minimum
Default
Maximum
Active unit loses power or stops normal operation.
800 milliseconds
15 seconds
45 seconds
Active unit main board interface link down.
500 milliseconds
5 seconds
15 seconds
Active unit 4GE card interface link down.
2 seconds
5 seconds
15 seconds
Active unit IPS or CSC card fails.
2 seconds
2 seconds
2 seconds
Active unit interface up, but connection problem
causes interface testing.
5 seconds
25 seconds
75 seconds
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......