cisco ASA/PIX failover and VPN, failover IP access problem


I have a problem and I'd like to ask for some assistance.

  • Site B - failover - works fine I configured two ASAs 5550 for failover with following schematic setup:

interface outside ip address standby interface inside ip address standby I configured stateful failover - it all works fine

  • Side A and Side B - VPN - works fine Now I configured

- VPN between site A - and site B

- I can communicate my management inside network on site B

- VPN works fine I can access (and manage via snmp, ssh) IP (active standby) from as well as any other machines on layer.

  • The problem - access to standby inside IP from management network

I cannot access standby inside IP - from (via VPN) Standby device maintains VPN SA and tcp states tables. When I think about this it makes sense - standby is standby and it is supposed to work in case of active failure, so when I try to access intside IP of standby device it tries to send traffic back via VPN which is working only on active device.

My question is - is there any way to manage standby device via inside IP (via VPN), or the only way is to use outside IP?

thanks in advance


Reply to
Loading thread data ... Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.