Active Active Failover Cont
Traffic
Traffic
Active/Active Failover
Traffic
Traffic
Unit A: Unit B:
Failed/Standby Active/Active
Under failed conditions, Unit A determines outside interface on CTX1 has failed.
• CTX1 is placed in failed state.
• Unit A has one failed and one standby context. Unit B, CTX1 becomes active.
• Unit B has two active contexts.
• Both active contexts pass traffic. Failover can be context-based or unit-based.
Unit A: Unit B:
Failed/Standby Active/Active
Under failed conditions, Unit A determines outside interface on CTX1 has failed.
• CTX1 is placed in failed state.
• Unit A has one failed and one standby context. Unit B, CTX1 becomes active.
• Unit B has two active contexts.
• Both active contexts pass traffic. Failover can be context-based or unit-based.
© 2005 Cisco Systems, Ii
In the previous example, in Unit A, CTX1 was active while CTX2 was standby. In Unit B, CTX1 was standby while CTX2 was active. Active/active failover logic enables each security appliance to determine whether a failure is context-based or unit-based. If an active context fails, the active context transitions to a failed state. In the peer security appliance, the standby context transitions from standby to active. For example, in the figure, if Unit A interface e0 fails, Unit A can determine that the failure is a context-based failure. Unit A places CTX1 in a failed state. Unit A can communicate with Unit B about the change in state of CTX1. Unit B changes the state of its CTX1 to active. After the state change, both of the Unit B contexts are active and passing traffic. Failover can be context-based or unit-based. When a failure affects the whole unit, the peer unit can take over by activating any standby contexts and start processing 100 percent of the traffic.
fw2(config)# interface ethernet2 fw2(config-if)# no shut fw2(config)# failover lan interface LANFAIL ethernet2
fw2(config)# failover interface ip LANFAIL 172.17.1.1 255.255.255.0 standby 172.17.1.7 fw2(config)# failover lan enable fw2(config)# failover link LANFAIL ethernet2 fw2(config)# failover lan key 1234567
fw2(config)# interface ethernet2 fw2(config-if)# no shut fw2(config)# failover lan interface LANFAIL ethernet2
fw2(config)# failover interface ip LANFAIL 172.17.1.1 255.255.255.0 standby 172.17.1.7 fw2(config)# failover lan enable fw2(config)# failover link LANFAIL ethernet2 fw2(config)# failover lan key 1234567
© 2005 Cisco Systems, Ii
Failover link is used to communicate unit health, interface health, switchover messages, configuration re-synchronization, and so on. To configure active/active failover, both security appliances must be in multimode. The administrator configures the failover link in the system configuration of the primary failover unit. Before configuring the failover link, be sure that the failover link interface is not in administrative shutdown. In the example in the figure, the administrator configures both security appliances as follows:
■ Removes the failover link interface, interface e2, from administrative shutdown
■ Identifies the name of the failover link and the failover link interface
■ Configures the failover link IP address and standby address
■ Enables LAN-based failover
■ Enables stateful failover on LANFAIL link
■ Specifies the shared secret key for encrypted and authenticated communications between failover pairs
Do not enable failover until the failover groups are configured.
Primary
Primary
Secondary
Group 1
Active/active failover adds support for failover group.
Failover is performed on a unit or group level.
Secondary
Group 1
Active/active failover adds support for failover group.
Failover is performed on a unit or group level.
A group is comprised of one or more contexts.
Each failover group contains separate state machines to keep track of the group failover state.
fw2(config)# failover group 1 fw2(config-fover-group)# primary fw2(config)# failover group 2 fw2(config-fover-group)# secondary
© 2005 Cisco Systems, Ii
In active/standby failover, failover is performed on a unit basis. One unit is active while the other unit is a standby unit. In active/active failover, failover is performed on a context basis. One context is active while the peer context is in standby state. ASA and PIX Security Appliance software release 7.0 introduces the concept of the failover group. Each security appliance supports up to two failover groups. You can join one or more contexts to a failover group. For example, context CTX1, CTX2, and CTX3 can join Group 1 while context CTX4 and CTX5 can join Group 2. The security appliance uses failover groups to manage contexts. Each failover group contains separate state machines to keep track of their context failover states. In the example in the figure, there are two failover groups, Group 1 and Group 2. Context CTX1 joins Group 1 and CTX2 joins Group 2. Group 1 monitors the health of CTX1 and Group 2 monitors the health of CTX2 across both security appliances. Failover can occur on a group or system basis.
You can configure failover Group 1 and Group 2 attributes using the failover group command. The failover group command can only be added while the administrator is in multimode system configuration and failover is disabled.
Entering the failover group command places you in the failover group subcommand mode. The primary, secondary, preempt, replication http, interface-policy, and polltime interface commands are available in the failover group subcommand mode. Use the exit command to return to global configuration mode.
failover group num primaryjsecondary preempt [<preempt_delay_in_seconds>] replication http polltime interface <seconds> interface-policy N[%]
|
primary |
Gives the primary unit higher priority. |
|
secondary |
Gives the secondary unit higher priority. |
|
Polltime interface |
Specifies interface polling interval. |
|
preempt |
Allows preemption of lower priority active unit. |
|
replication http |
Enables HTTP session replication for the selected failover group. |
|
mac address |
Specifies virtual MAC addresses for a physical interface. |
|
interface-policy |
Sets the policy for failover due to interface failures. |
This information should be configured in the primary unit only.
This information should be configured in the primary unit only.
Continue reading here: Configure the Security Appliance to Use ASDM
Was this article helpful?