Deploy Cisco ASA 55xx in Active / Standby Failover
Nov17

Deploy Cisco ASA 55xx in Active / Standby Failover

KB ID 0000048  Problem You want to deploy 2 Cisco ASA 55xx Series firewalls in an Active/Standby failover configuration. Solution Assumptions. Hardware on both ASA firewalls is identical. The correct license’s for failover are installed on both firewalls. The same software versions are installed on both firewalls. You have your PRIMARY firewall set up and running correctly (Everything works!). In this example the firewalls were...

Read More
Cisco ASA – Active / Active Failover
Dec10

Cisco ASA – Active / Active Failover

KB ID 0001114 Usually when I’m asked to setup Active/Active I cringe, not because its difficult, its simply because people assume active/active is better than active/standby. I hear comments like ‘we have paid for both firewalls lets use them’, or ‘I want to sweat both assets’. The only real practical use cases I can think of for Active /Active are; You have a multi-tenancy environment and want to offer...

Read More
Cisco ASA – I Cannot Ping External Addresses?  (Troubleshooting ICMP)
Nov17

Cisco ASA – I Cannot Ping External Addresses? (Troubleshooting ICMP)

KB ID 0000914  Problem Considering we use ICMP to test connectivity, the fact that it is not a stateful protocol can be a major pain! Last week one of my colleagues rang me up and said, “Can you jump on this firewall, I’ve got no comms, and I cant ping external IP addresses. I can ping the internet from the firewall and I can ping internal IP addresses form the firewall”. Solution 1. Before we start, lets get the basics...

Read More