{"id":244,"date":"2015-01-12T08:12:59","date_gmt":"2015-01-12T08:12:59","guid":{"rendered":"http:\/\/www.balajibandi.com\/?p=244"},"modified":"2017-08-25T09:18:46","modified_gmt":"2017-08-25T08:18:46","slug":"asa-activestandby-single-mode-setup","status":"publish","type":"post","link":"https:\/\/www.balajibandi.com\/?p=244","title":{"rendered":"ASA Active\/Standby Single mode setup"},"content":{"rendered":"<p><span style=\"text-decoration: underline;\"><strong>ASA Active\/Standby Single mode setup<\/strong><\/span><\/p>\n<p>HLD diagram for reference :<\/p>\n<p id=\"oKreozG\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-459 \" src=\"http:\/\/www.balajibandi.com\/wp-content\/uploads\/2017\/08\/img_599fd26491687.png\" alt=\"\" width=\"450\" height=\"489\" srcset=\"https:\/\/www.balajibandi.com\/wp-content\/uploads\/2017\/08\/img_599fd26491687.png 616w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2017\/08\/img_599fd26491687-276x300.png 276w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><\/p>\n<p><strong>FW1 simple config :<\/strong><\/p>\n<p>config t<br \/>\n!<br \/>\nhostname FW1<br \/>\n!<br \/>\ninterface Ethernet0<br \/>\nnameif management<br \/>\nsecurity-level 0<br \/>\nip address 192.168.1.65 255.255.255.0<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Ethernet1<br \/>\nchannel-group 1 mode active<br \/>\nno nameif<br \/>\nno security-level<br \/>\nno ip address<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Ethernet2<br \/>\nchannel-group 1 mode active<br \/>\nno nameif<br \/>\nno security-level<br \/>\nno ip address<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Ethernet3<br \/>\nchannel-group 1 mode active<br \/>\nno nameif<br \/>\nno security-level<br \/>\nno ip address<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Port-channel1<br \/>\nno nameif<br \/>\nno security-level<br \/>\nno ip address<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Port-channel1.200<br \/>\nvlan 200<br \/>\nnameif dmz<br \/>\nsecurity-level 0<br \/>\nip address 10.10.20.254 255.255.255.0<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Port-channel1.300<br \/>\nvlan 300<br \/>\nnameif inside<br \/>\nsecurity-level 100<br \/>\nip address 10.10.30.254 255.255.255.0<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Port-channel1.400<br \/>\nvlan 400<br \/>\nnameif outside<br \/>\nsecurity-level 0<br \/>\nip address 10.10.40.254 255.255.255.0<br \/>\nno shutdown<br \/>\n!<br \/>\nmtu dmz 1500<br \/>\nmtu inside 1500<br \/>\nmtu outside 1500<br \/>\nmtu management 1500<\/p>\n<p>http server enable<br \/>\nhttp 192.168.1.0 255.255.255.0 management<br \/>\nmanagement-access management<br \/>\nusername cisco password 3USUcOPFUiMCO4Jk encrypted<br \/>\n!<br \/>\n<strong>ASA ACTIVE \/ Standby<\/strong><br \/>\n=======================<\/p>\n<p>FW1#<\/p>\n<p>config t<br \/>\ninterface Ethernet4<br \/>\nno shutdown<\/p>\n<p>failover lan unit primary<br \/>\nfailover lan interface FAILOVER Ethernet4<\/p>\n<p>failover link FAILOVER Ethernet4<\/p>\n<p>failover interface ip FAILOVER 40.40.40.1 255.255.255.0 standby 40.40.40.2<\/p>\n<p>failover<\/p>\n<p>interface Port-channel1.300<br \/>\nip address 20.20.20.254 255.255.255.0 standby 20.20.20.253<\/p>\n<p>interface Port-channel1.400<br \/>\nip address 192.168.1.65 255.255.255.0 standby 192.168.1.66<br \/>\n<strong>FW2 ( Standby)<\/strong><br \/>\n<strong>==============<\/strong><\/p>\n<p>failover lan unit secondary<br \/>\nfailover lan interface FAILOVER Ethernet4<br \/>\nfailover link FAILOVER Ethernet4<br \/>\nfailover interface ip FAILOVER 40.40.40.1 255.255.255.0 standby 40.40.40.2<br \/>\nfailover<\/p>\n<p>interface Ethernet4<br \/>\nno shutdown<br \/>\n<strong>MONITORING INTERFACE <\/strong><br \/>\n<strong>====================<\/strong><\/p>\n<p>monitor-interface inside<br \/>\nmonitor-interface outside<br \/>\nmonitor-interface management<\/p>\n<p><strong>TESTING FAILOVER<\/strong><br \/>\n<strong>================<\/strong><\/p>\n<p>FW1\/pri\/act(config)# no failover active<br \/>\nFW1\/pri\/act(config)# Waiting for the earlier webvpn instance to terminate&#8230;<br \/>\nPrevious instance shut down. Starting a new one.<\/p>\n<p>Switching to Standby<\/p>\n<p>FW1\/pri\/stby(config)#<br \/>\nFW1\/pri\/stby(config)#<br \/>\nFW1\/pri\/stby(config)# fail<br \/>\nFW1\/pri\/stby(config)# failover ac<br \/>\nFW1\/pri\/stby(config)# show mon<br \/>\nFW1\/pri\/stby(config)# show monitor-interface<br \/>\nThis host: Primary &#8211; Standby Ready<br \/>\nInterface management (192.168.1.66): Normal (Monitored)<br \/>\nInterface inside (20.20.20.253): Normal (Monitored)<br \/>\nInterface outside (10.10.40.253): Normal (Monitored)<br \/>\nOther host: Secondary &#8211; Active<br \/>\nInterface management (192.168.1.65): Normal (Monitored)<br \/>\nInterface inside (20.20.20.254): Normal (Monitored)<br \/>\nInterface outside (10.10.40.254): Normal (Monitored)<br \/>\nFW1\/pri\/stby(config)# failover active<br \/>\nWaiting for the earlier webvpn instance to terminate&#8230;<br \/>\nPrevious instance shut down. Starting a new one.<\/p>\n<p>Switching to Active<\/p>\n<p>FW1\/pri\/act# show monitor-interface<br \/>\nThis host: Primary &#8211; Active<br \/>\nInterface management (192.168.1.65): Normal (Monitored)<br \/>\nInterface inside (20.20.20.254): Normal (Monitored)<br \/>\nInterface outside (10.10.40.254): Normal (Monitored)<br \/>\nOther host: Secondary &#8211; Standby Ready<br \/>\nInterface management (192.168.1.66): Normal (Monitored)<br \/>\nInterface inside (20.20.20.253): Normal (Monitored)<br \/>\nInterface outside (10.10.40.253): Normal (Monitored)<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Updated :<\/strong><\/p>\n<p><strong>Tuning Fail over Timers :<\/strong><\/p>\n<p>500msec and 2sc hold timer<\/p>\n<p>failover polltime unit msec 500 holdtime 2<br \/>\nfailover polltime interface msec 500 holdtime 5<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/i.stack.imgur.com\/vHfZ0.png\" alt=\"enter image description here\" width=\"395\" height=\"176\" \/><\/p>\n<p><strong>After tuning the timers only 1 ping lost<\/strong><\/p>\n<p id=\"vItdfdh\"><img loading=\"lazy\" decoding=\"async\" width=\"345\" height=\"122\" class=\"alignnone size-full wp-image-465 \" src=\"http:\/\/www.balajibandi.com\/wp-content\/uploads\/2017\/08\/img_599fdd5dc1a2a.png\" alt=\"\" srcset=\"https:\/\/www.balajibandi.com\/wp-content\/uploads\/2017\/08\/img_599fdd5dc1a2a.png 345w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2017\/08\/img_599fdd5dc1a2a-300x106.png 300w\" sizes=\"auto, (max-width: 345px) 100vw, 345px\" \/><\/p>\n<p><strong>Monitoring the interface :<\/strong><\/p>\n<p>You need to mentioned monitor interface IP to monitor, example :<\/p>\n<p>interface Port-channel1.300<br \/>\nvlan 300<br \/>\nnameif inside<br \/>\nsecurity-level 100<br \/>\nip address 10.10.30.254 255.255.255.0 standby 10.10.30.253<br \/>\nno shutdown<br \/>\n!<br \/>\ninterface Port-channel1.400<br \/>\nvlan 400<br \/>\nnameif outside<br \/>\nsecurity-level 0<br \/>\nip address 10.10.40.254 255.255.255.0\u00a0standby 10.10.40.253<\/p>\n<p><strong>Good Luck ! Happy Reading !!<\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ASA Active\/Standby Single mode setup HLD diagram for reference : FW1 simple config : config t ! hostname FW1 ! interface Ethernet0 nameif management security-level 0 ip address 192.168.1.65 255.255.255.0 no shutdown ! interface Ethernet1 channel-group 1 mode active no nameif no security-level no ip address no shutdown ! interface Ethernet2 channel-group 1 mode active [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,2],"tags":[],"class_list":["post-244","post","type-post","status-publish","format-standard","hentry","category-ccie-sec","category-cisco"],"_links":{"self":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=244"}],"version-history":[{"count":5,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/244\/revisions"}],"predecessor-version":[{"id":466,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/244\/revisions\/466"}],"wp:attachment":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}