<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco ASA 5505: Active/Standby Failover Configuration</title>
	<atom:link href="http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/feed/" rel="self" type="application/rss+xml" />
	<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/</link>
	<description></description>
	<lastBuildDate>Thu, 17 May 2012 14:52:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Al</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-2517</link>
		<dc:creator>Al</dc:creator>
		<pubDate>Wed, 29 Feb 2012 20:13:45 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-2517</guid>
		<description>Assignment of the a physical interface to the failover vlan is missing

!
interface Vlan32
description LAN Failover Interface
no shutdown
!
interface e0/0
 switchport access vlan 32
 no shut
!</description>
		<content:encoded><![CDATA[<p>Assignment of the a physical interface to the failover vlan is missing</p>
<p>!<br />
interface Vlan32<br />
description LAN Failover Interface<br />
no shutdown<br />
!<br />
interface e0/0<br />
 switchport access vlan 32<br />
 no shut<br />
!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-2498</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Sat, 11 Feb 2012 12:03:45 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-2498</guid>
		<description>Nice work - but one thing that isn&#039;t described in  here is the assignment of the vlan to an ethernet port or any switch configuration that is recommended such as stp, no channel group and no trunk.</description>
		<content:encoded><![CDATA[<p>Nice work &#8211; but one thing that isn&#8217;t described in  here is the assignment of the vlan to an ethernet port or any switch configuration that is recommended such as stp, no channel group and no trunk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cipher</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-2458</link>
		<dc:creator>Cipher</dc:creator>
		<pubDate>Sat, 14 Jan 2012 16:19:05 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-2458</guid>
		<description>Great work, thanks !</description>
		<content:encoded><![CDATA[<p>Great work, thanks !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kupa</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-2440</link>
		<dc:creator>Kupa</dc:creator>
		<pubDate>Sun, 01 Jan 2012 09:07:18 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-2440</guid>
		<description>This is an excellent document and easy to follow. I configured my 2 ASA running version 8.3 however when i do Show failover command, the other host which is primary on standby ready 

Shows 
inside interface (0.0.0.0), normal
Outside interface (0.0.0.0) , normal

Why is it not showing the specific addresses?</description>
		<content:encoded><![CDATA[<p>This is an excellent document and easy to follow. I configured my 2 ASA running version 8.3 however when i do Show failover command, the other host which is primary on standby ready </p>
<p>Shows<br />
inside interface (0.0.0.0), normal<br />
Outside interface (0.0.0.0) , normal</p>
<p>Why is it not showing the specific addresses?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firewall: Configuring Active/Standby failover using ASA5505 pair. &#171; The Network Journal</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-2054</link>
		<dc:creator>Firewall: Configuring Active/Standby failover using ASA5505 pair. &#171; The Network Journal</dc:creator>
		<pubDate>Sun, 01 May 2011 18:27:45 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-2054</guid>
		<description>[...] http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/" rel="nofollow">http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robin</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-1934</link>
		<dc:creator>Robin</dc:creator>
		<pubDate>Mon, 14 Mar 2011 17:17:09 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-1934</guid>
		<description>Hi,

I am currently running 8.2 IOS with bith ASA 5505 in Transparent mode. 

sh run
: Saved
:
ASA Version 8.2(1)
!
firewall transparent
hostname pro-asa-02
domain-name tmi-cms.local
enable password 5REOWXSNDmF7qN69 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Vlan2
 no nameif
 no security-level
!
interface Vlan5
 nameif outside
 security-level 0
!
interface Vlan40
 nameif inside
 security-level 100

When I am trying to add the &quot;Failover&quot; it is showing error as follows.

pro-asa-02(config)# failover lan interface Vlan2
ERROR: Legacy syntax is only supported for configure conversion.
Usage: [no] failover
        [no] failover polltime [unit] [msec]  [holdtime [msec] ]
        [no] failover polltime interface [msec]  [holdtime ]
        [no] failover replication http
        [no] failover lan unit primary&#124;secondary
        [no] failover interface ip    standby 
        [no] failover interface-policy [%]
        [no] failover key &#124;{hex }
        [no] failover lan interface  [.]
        [no] failover link  [[.]]
        [no] failover mac address   
        [no] failover timeout 
        [no] failover active
        failover reset
        failover reload-standby
        show failover [history&#124;interface&#124;state&#124;statistics]
        show running-config failover
        clear configure failover
        clear failover statistics

It is saying to add the  But I don&#039;t have Interface name for failover &quot;Vlan2&quot;. Since it is a transparent firewall, it is not allowing me to add more than 2 &quot;nameif&quot; or Interface Name to add.

Please help me to resolve this issue. 
Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I am currently running 8.2 IOS with bith ASA 5505 in Transparent mode. </p>
<p>sh run<br />
: Saved<br />
:<br />
ASA Version 8.2(1)<br />
!<br />
firewall transparent<br />
hostname pro-asa-02<br />
domain-name tmi-cms.local<br />
enable password 5REOWXSNDmF7qN69 encrypted<br />
passwd 2KFQnbNIdI.2KYOU encrypted<br />
names<br />
!<br />
interface Vlan2<br />
 no nameif<br />
 no security-level<br />
!<br />
interface Vlan5<br />
 nameif outside<br />
 security-level 0<br />
!<br />
interface Vlan40<br />
 nameif inside<br />
 security-level 100</p>
<p>When I am trying to add the &#8220;Failover&#8221; it is showing error as follows.</p>
<p>pro-asa-02(config)# failover lan interface Vlan2<br />
ERROR: Legacy syntax is only supported for configure conversion.<br />
Usage: [no] failover<br />
        [no] failover polltime [unit] [msec]  [holdtime [msec] ]<br />
        [no] failover polltime interface [msec]  [holdtime ]<br />
        [no] failover replication http<br />
        [no] failover lan unit primary|secondary<br />
        [no] failover interface ip    standby<br />
        [no] failover interface-policy [%]<br />
        [no] failover key |{hex }<br />
        [no] failover lan interface  [.]<br />
        [no] failover link  [[.]]<br />
        [no] failover mac address<br />
        [no] failover timeout<br />
        [no] failover active<br />
        failover reset<br />
        failover reload-standby<br />
        show failover [history|interface|state|statistics]<br />
        show running-config failover<br />
        clear configure failover<br />
        clear failover statistics</p>
<p>It is saying to add the  But I don&#8217;t have Interface name for failover &#8220;Vlan2&#8243;. Since it is a transparent firewall, it is not allowing me to add more than 2 &#8220;nameif&#8221; or Interface Name to add.</p>
<p>Please help me to resolve this issue.<br />
Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MMJP &#187; Cisco ASA 5505: Active/Standby Failover Configuration</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-1917</link>
		<dc:creator>MMJP &#187; Cisco ASA 5505: Active/Standby Failover Configuration</dc:creator>
		<pubDate>Tue, 22 Feb 2011 14:08:22 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-1917</guid>
		<description>[...] Cisco ASA 5505: Active/Standby Failover Configuration [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco ASA 5505: Active/Standby Failover Configuration [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-1101</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Thu, 29 Apr 2010 11:14:47 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-1101</guid>
		<description>Thanks for you time to write this down for us. 
I read the Cisco document over and over but couldn`t get it right. Works like a charm now!!</description>
		<content:encoded><![CDATA[<p>Thanks for you time to write this down for us.<br />
I read the Cisco document over and over but couldn`t get it right. Works like a charm now!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jm</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-1041</link>
		<dc:creator>jm</dc:creator>
		<pubDate>Sun, 14 Feb 2010 09:18:41 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-1041</guid>
		<description>hi
what is the failover time.  I.E. when the primary unit fails, how long before the standby becomes active and takes over.  I assume state is passed between the units
thanks</description>
		<content:encoded><![CDATA[<p>hi<br />
what is the failover time.  I.E. when the primary unit fails, how long before the standby becomes active and takes over.  I assume state is passed between the units<br />
thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vince</title>
		<link>http://linuxsysadminblog.com/2009/02/cisco-asa-5505-activestandby-failover-configuration/comment-page-1/#comment-878</link>
		<dc:creator>vince</dc:creator>
		<pubDate>Mon, 07 Dec 2009 21:20:16 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=327#comment-878</guid>
		<description>I don&#039;t understand what you mean by:

&quot;You can either cross-connect this between the 2 ASAs or you can use a switch with a dedicated vlan for this. The later one is preferred as it will more accurately detect if one ASA is down&quot;

How is the VLAN method preferred?  What if the switch that the VLAN is connected to fails?  I would think the cross over cable would give the &#039;truest&#039; indication of a firewall failure</description>
		<content:encoded><![CDATA[<p>I don&#8217;t understand what you mean by:</p>
<p>&#8220;You can either cross-connect this between the 2 ASAs or you can use a switch with a dedicated vlan for this. The later one is preferred as it will more accurately detect if one ASA is down&#8221;</p>
<p>How is the VLAN method preferred?  What if the switch that the VLAN is connected to fails?  I would think the cross over cable would give the &#8216;truest&#8217; indication of a firewall failure</p>
]]></content:encoded>
	</item>
</channel>
</rss>

