1-23
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring a Cluster of ASAs
Licensing Requirements for ASA Clustering
FTP
• If FTP data channel and control channel flows are owned by different cluster members, the data
channel owner will periodically send idle timeout updates to the control channel owner and update
the idle timeout value. However, if the control flow owner is reloaded, and the control flow is
re-hosted, the parent/child flow relationship will not longer be maintained; the control flow idle
timeout will not be updated.
• If you use AAA for FTP access, then the control channel flow is centralized on the master unit.
Cisco TrustSec
Only the master unit learns security group tag (SGT) information. The master unit then populates the
SGT to slaves, and slaves can make a match decision for SGT based on the security policy.
Licensing Requirements for ASA Clustering
Prerequisites for ASA Clustering
Switch Prerequisites
• Be sure to complete the switch configuration before you configure clustering on the ASAs.
• Table 1-2 lists supported external hardware and software to interoperate with ASA clustering.
ASA Prerequisites
• Provide each unit with a unique IP address before you join them to the management network.
–
See Chapter 1, “Getting Started,” for more information about connecting to the ASA and setting
the management IP address.
–
Except for the IP address used by the master unit (typically the first unit you add to the cluster),
these management IP addresses are for temporary use only.
Model License Requirement
ASA 5580,
ASA 5585-X
Cluster License, supports up to 8 units.
A Cluster license is required on each unit. For other feature licenses, cluster units do not require the
same license on each unit. If you have feature licenses on multiple units, they combine into a single
running ASA cluster license.
Note Each unit must have the same encryption license.
All other models No support.
Table 1-2 External Hardware and Software Dependencies for ASA Clustering
External Hardware External Software ASA Version
Nexus 7000 NXOS 5.2(5) 9.0(1) and later.
Catalyst 6500 with Supervisor 32,
720, and 720-10GE
IOS 12.2(33)SXI7, SXI8, and SXI9 9.0(1) and later.