19-16
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter19 Configuring the ASA 5585-X IPS SSP
Failover Scenarios
Failover Scenarios
The following failover scenarios apply to the ASA 5585-X in the event of configuration changes,
signature/signature engine updates, service packs, and SensorApp crashes on the ASA 5585-X IPS SSP.
Single ASA 5585-X in Fail-Open Mode
If the ASA is configured in fail-open mode for the ASA 5585-X IPS SSP, and the
ASA 5585-X IPS SSP experiences a configuration change or signature/signature engine update,
traffic is passed through the ASA without being inspected.
If the ASA is configured in fail-open mode for the ASA 5585-X IPS SSP, and the
ASA 5585-X IPS SSP experiences a SensorApp crash or a service pack upgrade, traffic is passed
through the ASA without being inspected.
Single ASA 5585-X in Fail-Close Mode
If the ASA is configured in fail-close mode for the ASA 5585-X IPS SSP, and the
ASA 5585-X IPS SSP experiences a configuration change or a signature/signature engine update,
traffic is stopped from passing through the ASA.
If the ASA is configured in fail-close mode for the ASA 5585-X IPS SSP, and the
ASA 5585-X IPS SSP experiences a SensorApp crash or a service pack upgrade, traffic is stopped
from passing through the ASA.
Two ASA 5585-Xs in Fail-Open Mode
If the ASAs are configured in fail-open mode and if the ASA5585-X IPS SSP on the active ASA
experiences a configuration change or a signature/signature engine update, traffic is still passed
through the active ASA without being inspected. Failover is not triggered.
If the ASAs are configured in fail-open mode, and if the ASA 5585-X IPS SSP on the active ASA
experiences a SensorApp crash or a service pack upg rade, failover is triggered and traffic passes
through the ASA 5585-X IPS SSP that was previously the standby ASA5585- XIPS SSP.
Two ASA 5585-Xs in Fail-Close Mode
If the ASAs are configured in fail-close mode, and if the ASA 5585-X IPSSSP on the active ASA
experiences a configuration change or a signature/signa ture engine update, traffic is stopped from
passing through the active ASA. No failover is triggered.
If the ASAs are configured in fail-close mode, and if the ASA 5585-X IPSSSP on the active ASA
experiences a SensorApp crash or a service pack upg rade, failover is triggered and traffic passes
through the ASA 5585-X IPS SSP that was previously the standby for the ASA5585-X IPS SSP.
Configuration Examples
Use the following configuration for the primary ASA:
interface GigabitEthernet0/7
description LAN Failover Interface
failover
failover lan unit primary
failover lan interface folink GigabitEthernet0/7
failover interface ip folink 172.27.48.1 255.255.255.0 standby 172.27.48.2
Use the following configuration for the secondary ASA:
interface GigabitEthernet0/7
description LAN Failover Interface