CHAPTER
 
1-1
Cisco ASA Series CLI Configuration Guide
 
1
Information About Failover
This chapter provides an overview of the failover features that enable you to achieve high availability on 
the Cisco 5500 series ASAs. For information about configuring high availability, see Chapter 1, 
“Configuring Active/Active Failover” or Chapter 1, “Configuring Active/Standby Failover.”
This chapter includes the following sections:
• Introduction to Failover and High Availability, page 1-1
• Failover System Requirements, page 1-2
• Failover and Stateful Failover Links, page 1-3
• Active/Active and Active/Standby Failover, page 1-8
• Stateless (Regular) and Stateful Failover, page 1-9
• Intra- and Inter-Chassis Module Placement for the ASA Services Module, page 1-11
• Transparent Firewall Mode Requirements, page 1-15
• Auto Update Server Support in Failover Configurations, page 1-16
• Failover Health Monitoring, page 1-18
• Failover Times, page 1-20
• Failover Messages, page 1-20
Introduction to Failover and High Availability
Configuring high availability requires two identical ASAs connected to each other through a dedicated 
failover link and, optionally, a Stateful Failover link. The health of the active interfaces and units is 
monitored to determine if specific failover conditions are met. If those conditions are met, failover 
occurs.
The ASA supports two failover configurations, Active/Active failover and Active/Standby failover. Each 
failover configuration has its own method for determining and performing failover.
With Active/Active failover, both units can pass network traffic. This also lets you configure traffic 
sharing on your network. Active/Active failover is available only on units running in multiple context 
mode. 
With Active/Standby failover, only one unit passes traffic while the other unit waits in a standby state. 
Active/Standby failover is available on units running in either single or multiple context mode. 
Both failover configurations support stateful or stateless (regular) failover.