Welcome to Firewall.cx   Cisco Technical Knowledgebase
Modules
· Home
· Alternative Menu
· Amazon
· Cisco Decrypter
· Cisco Lab Partners
· Feedback
· Forums
· Max Arcade
· Private Messages
· Recommend Us
· Statistics
· Stories Archive
· Submit News
· Surveys
· Topics
· Web Links
· Your Account
 
Cisco Knowledgebase Articles
 
Site Info
Your IP: 38.107.191.112

Welcome, Anonymous
Nickname
Password

· Register
· Lost Password
Server Date/Time
31 July 2010 14:02:41 EEST (GMT +3)
 
Top Downloads
 
Gold Lab Partners


 
Firewall.cx: Forums

Firewall.cx :: View topic - Forward traffic from one internal asa to another
Forums Home
Forum FAQ :: Search :: Memberlist :: Usergroups
Profile :: Log in to check your private messages :: Log in

View next topic
View previous topic
Post new topic   Reply to topic
Author Message
mdn
New Member
New Member


Joined: Mar 11, 2010
Posts: 1

PostPosted: Thu Mar 11, 2010 12:18 pm    Post subject: Forward traffic from one internal asa to another Reply with quote

Please anyone can help regard,
I have 2 ASA 5520
one ASA 5520 working with old IOS
another ASA 5520 Standby disconnected with latest IOS.
I want to test Standby ASA working or not same as Live ASA.
Schenario. from internet>switch>ASA Live>Switch>our computer so please can we forward all traffic from Live ASA to Standby ASA to Our network connected switch without down time

Please reply..
Back to top
View user's profile Send private message
krik
Occasional Member
Occasional Member


Joined: Sep 05, 2006
Posts: 66
Location: Belgium

PostPosted: Sat Mar 13, 2010 10:22 am    Post subject: Reply with quote

Hi,

As far as I know, the standby ASA will not process traffic as long as the active member is alive or has not resign.

I see three possibilities :

1) Test the new IOS in a lab. Best would be to have a spare ASA in the lab. Otherwise you could also remove the standby ASA from live network and make it active in the lab...
2) Perform a failover to the standby, verify everything is working fine then upgrade the second ASA to the same IOS version
3) Break the cluster to have the two ASA Active daisy chain them (some re-IP required). However I do not see any advantage on the proposal 2.

I hope this helps
_________________
Christophe Lemaire
http://www.exp-networks.be/blog/
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum




smartDark Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group
 
Forums ©

© Copyright 2000-2010 Firewall.cx - All Rights Reserved

Copyright of all documents and images belonging to this site by Firewall.cx. Information contained on this site is copyrighted material.

It is illegal to copy or redistribute this information in any way without the written consent of Firewall.cx


Firewall.cx disclaims any responsibility for software and information obtained through this site or its links.


Page Generation: 0.35 Seconds