cisco ASA/PIX failover and VPN, failover IP access problem

Discussion in 'Cisco' started by Pit, Aug 27, 2008.

  1. Pit

    Pit Guest


    I have a problem and I'd like to ask for some assistance.

    * Site B - failover - works fine
    I configured two ASAs 5550 for failover with following schematic

    interface outside
    ip address standby
    interface inside
    ip address standby
    I configured stateful failover - it all works fine

    * Side A and Side B - VPN - works fine
    Now I configured
    - VPN between site A - and site B
    - I can communicate my management inside network on
    site B
    - VPN works fine I can access (and manage via snmp, ssh) IP
    (active standby) from as well as any other machines on layer.

    * The problem - access to standby inside IP from management network

    I cannot access standby inside IP - from
    (via VPN)
    Standby device maintains VPN SA and tcp states tables.
    When I think about this it makes sense - standby is standby and it is
    supposed to work in case of active failure, so when I try to access
    intside IP of standby device it tries to send traffic back via VPN
    which is working only on active device.

    My question is - is there any way to manage standby device via inside
    IP (via VPN), or the only way is to use outside IP?

    thanks in advance

    Pit, Aug 27, 2008
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.