- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-04-2015 03:14 PM
I am setting up a HA pair of 5060s in vwire mode between two Cisco ASA's and the internal switch. the ASAs are set up has HA.
What is the best way to set up the 5060s in HA to ensure they notice when the ASA fails. I do not want a scenario where the ASA fails but the Palo does not. Then the secondary ASA will be active forwarding traffic to the secondary passive PA that will drop all packets.
Is A/A HA the preferred method or using link and path monitoring on the PA?
08-05-2015 02:42 AM
Correct, you need a unique address for each of the ASA nodes to determine it is not available.
08-04-2015 03:22 PM
If you setup the pair as A/A then you really don't need to do anything else. Whatever happens on the ASA a valid path will exist. The disadvantage here is that your HA3 link will need to be sized to accommodate double your max traffic. Sessions will be owned by the primary node and when failover occurs the traffic will start coming in and out the secondary path. But session inspection will happen on the primary so the traffic goes over the the primary inspected and returned to the secondary for egress. You will need to be sure you won't max out the link.
If you use A/P then link and path monitoring should be able to detect the lost of your primary path and trigger the failover.
08-04-2015 05:22 PM
Okay, sounds like A/P will be the answer.
I know how to set up link monitor. For Path monitoring I would have to ping an IP unique to each firewall correct?
08-05-2015 02:42 AM
Correct, you need a unique address for each of the ASA nodes to determine it is not available.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!