ASA 5540 CONFIGURATION FOR HIGH AVAILABILITY ACTIVE/STANDBY

CONFIGURATION FOR HIGH AVAILABILITY ACTIVE/STANDBY ON PRIMARY

**BRING INTERFACES UP & APPLY IP ADDRESSES**

-int g0

-no shut

-ip address xxx.x.xxx.xx 255.255.255.252 standby xxx.x.xxx.x

-nameif OUTSIDE

-description OUTSIDE PERIMITER

-int g1

-no shut

-ip address 10.0.10.1 255.255.255.0 standby 10.0.10.2

-nameif INSIDE

-description INSIDE RAD

-int g2

-no shut

-failover lan interface fail-g2 g2

-failover interface ip fail-g2 10.0.0.1 255.255.255.252 standby 10.0.0.2

-int g3

-no shut

-failover link stateful-g3 g3

-failover interface ip stateful-g3 10.1.1.1 255.255.255.252 standby 10.1.1.2

**SPECIFY THE KEY TO BE USED**

-failover key <key>

**TURN ON HTTP REPLICATION**

-failover replication http

**ASSIGN PRIMARY ROLE TO ASA**

-failover lan unit primary

**CHANGE PROMPT TO SHOW PRIMARY/SECONDARY & ACTIVE/STANDBY**

-prompt priority state

**ENABLE FAILOVER**

-failover

**VERIFY CONFIGURATION**

-show failover status

-show failover

 

CONFIGURATION FOR HIGH AVAILABILITY ACTIVE/STANDBY ON SECONDARY

**ONLY NEED TO CONFIGURE FAILOVER LINK**

-int g3

-no shut

-failover lan interface fail-g2 g2

-failover interface ip fail-g2 10.0.0.1 255.255.255.252 standby 10.0.0.2

-failover key <key>

-failover lan unit secondary

-failover

Posted in ASA Firewall, Network Security
2 comments on “ASA 5540 CONFIGURATION FOR HIGH AVAILABILITY ACTIVE/STANDBY
  1. Elie Fabs says:

    Fantastic commentary , I learned a lot from the specifics . Does someone know if I can get access to a sample a form copy to fill in ?

    • bullyvard says:

      Elie,

      I’m not 100% sure what you are asking, but there are sites that will allow you to rent equipment in the cloud by the hour so you can practice various configurations, if I understood your question correctly. The other option is to purchase a 5510 used on Craigslist from a company that is retiring their equipment. Building your own lab is always the best choice.

      Good Luck!

Leave a comment

  • An error has occurred; the feed is probably down. Try again later.
  • An error has occurred; the feed is probably down. Try again later.