Cisco ASA Firewall Active/Standby Failover Configuration

Поделиться
HTML-код
  • Опубликовано: 6 сен 2024
  • In this video I show how to configure a pair of Cisco ASA firewalls for Active/Standby Failover.
    Sample Configuration: www.rmtechcent...
    Did you find this content helpful? Let us know - www.rmtechcent...
    Website: www.rmtechcent...
    Contact: www.rmtechcent...
    Timeline:
    0:11 - Introduction/Topology Overview
    2:17 - Physical Equipment Overview
    3:20 - The Configuration
    15:50 - Additional Configuration (i.e. inside/outside interfaces, NAT, etc)

Комментарии • 16

  • @werong1842
    @werong1842 3 года назад +3

    Thank you for the video but i have a question whats the difference between Management and Statefull link?

    • @RMTechCentral
      @RMTechCentral  3 года назад +5

      Hello! Sorry for the extremely late reply, but if you are still looking for the answer to this question I'd be more than happy to help.
      Firstly, I think the question is probably more along the lines of the difference between the Failover Link and Stateful Link. I say this only because I used the Management interface for the Failover Link; it could have been any other interface but I decided to use Management0/0 for the video. Otherwise, the management interface would mostly likely be used for out of band management if used for its intended purpose.
      Now failover and stateful links are 2 different things... The failover link is what communicates failover/health information between the ASAs. So for example, if the primary ASA suffered a link failure, that would be communicated over the failover link and tell the secondary ASA to become active.
      The stateful link is something entirely different and also optional... this is the link that communicates stateful information such as firewall states and NAT mappings to the standby ASA. For example, say that the primary ASA is forwarding traffic. Firewall states are constantly being added, as well as NAT if you are running NAT on the ASA.
      Now, let's say that ASA fails and the standby unit become active. Connections would most likely be reset because the firewall states would not exist, so traffic coming from the outside to inside would be blocked and the sessions would need to be re-established.
      With a stateful link and all of that information being synced with the standby ASA, if it does become active, then sessions will not be reset and connection will not need to be re-established because all of those firewall states will have been replicated to that secondary ASA over the stateful link.
      I hope this helps and thanks for your question!

  • @ernestgrouns8710
    @ernestgrouns8710 2 года назад +2

    Thanks for the very well laid out and easy to follow instructions! One question I have regarding the outside interfaces... Do they always need to up-link to a layer 2 device? I can never get my ASA outside interface to show as "normal (monitored)" when I have it directly connected to a router interface. Only when I add a L2 switch between the ASA and the router will normal monitoring work. Every other topology I've seen shows the outside interface up-linking to a L2 switch as well. Any insight into this is appreciated, thanks!

    • @RMTechCentral
      @RMTechCentral  2 года назад +1

      Hey Ernest, thanks for the feedback! The reason why you need that layer 2 adjacency between ASAs is because the active and standby interfaces are on the same subnet. Let's say the active IP is 10.0.0.1 for the active firewall. If that link fails (or the firewall fails) the standby will take over for 10.0.0.1. By connecting those interfaces to individual L3 interfaces you have split that subnet, so you will end up having reachability issues. The L2 switch allows you to reach the active firewall regardless of which router the traffic came in on and you don't have to worry about blackholing traffic.
      Now, with that being said, I have configured this in the past the way you mentioned, however I was using the firewall links as transport links and running OSPF. In that scenario (though I don't believe it is best practice), I did not have an issue with monitoring on those links. If I remember correctly, the firewalls were connected to 2 L3 switches with a L3 link connecting those switches together. The standby ASA suspends the OSPF process, and therefore no traffic would be routed toward the secondary unless the primary failed. So you "should" be able to do it that way, but I would advise that the routers are connected together via a L3 link and you are running a routing protocol between the routers and ASAs.
      I can possibly lab this up again if I have a moment and see if I can reproduce the issue that you described.

    • @ernestgrouns8710
      @ernestgrouns8710 2 года назад +1

      @@RMTechCentral You have explained this perfectly, thanks so very much. It's all clicking now. I really appreciate the thorough explanation and response. Subscribed!!!

  • @rockinron5113
    @rockinron5113 2 года назад +1

    Great. Thanks!

  • @anasshanaah2884
    @anasshanaah2884 2 года назад

    Thank you so much for this video this was super helpful i appreciated, so could you give video about multiple context

  • @veerabsc
    @veerabsc 2 года назад

    Very good demonstration mate!!!

    • @RMTechCentral
      @RMTechCentral  2 года назад +1

      Thank you very much, I appreciate the feedback!

  • @ershadramezani6716
    @ershadramezani6716 2 года назад +1

    Thanks 🙏

  • @AndrewLennyMclean
    @AndrewLennyMclean Год назад

    Hi Rob, great video. Could I ask, when would you need to have a standby address configured for the outside interface? I'm trying to think of different scenarios, but none would need to '"know" the interface's IP? Also, whilst on the subject, does the outside interface on the active FW replicate to the standby FW?

  • @cuongtlam
    @cuongtlam Год назад

    Good video. Thank you.

  • @SquashMtb
    @SquashMtb 2 года назад

    Hi, Great video. ;). Once you disconnect the Inside cable a Asa switchover takes place, is that by default? that all interfaces are being monitored.

  • @titangaming9649
    @titangaming9649 2 года назад

    How does the config work? If I need to create an allow rule do I need to add that allow rule to both ASA's or does the secondary asa mirror the config of the primary?