Cisco Systems ASA 5585-X Network Router User Manual


  Open as PDF
of 2086
 
7-11
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter 7 Using the High Availability and Scalability Wizard
Configuring VPN Cluster Load Balancing with the High Availability and Scalability Wizard
Note When using encryption, you must have previously configured the load balancing inside
interface. If that interface is not enabled on the load balancing inside interface, an error message
appears when you try to configure cluster encryption.
If the load balancing inside interface is enabled when you configured cluster encryption, but is
disabled before you configure the participation of the device in the virtual cluster, an error
message appears when you check the Participate in Load Balancing Cluster check box, and
encryption is not enabled for the cluster.
Step 4 Specify the shared secret to between IPsec peers when you enable IPsec encryption. The value that you
enter appears as consecutive asterisk characters.
Step 5 Specify the priority assigned to this device within the cluster. The range is from 1 to 10. The priority
indicates the likelihood of this device becoming the virtual cluster master, either at startup or when an
existing master fails. The higher the priority set (for example, 10), the more likely that this device will
become the virtual cluster master.
Note If the devices in the virtual cluster are powered up at different times, the first device to be
powered up assumes the role of virtual cluster master. Because every virtual cluster requires a
master, each device in the virtual cluster checks when it is powered up to ensure that the cluster
has a virtual master. If none exists, that device assumes the role. Devices powered up and added
to the cluster later become secondary devices. If all the devices in the virtual cluster are powered
up simultaneously, the device with the highest priority setting becomes the virtual cluster master.
If two or more devices in the virtual cluster are powered up simultaneously, and both have the
highest priority setting, the one with the lowest IP address becomes the virtual cluster master.
Step 6 Specify the name or IP address of the public interface for this device.
Step 7 Specify the name or IP address of the private interface for this device.
Step 8 Check the Send FQDN to client instead of an IP address when redirecting check box to have the VPN
cluster master send a fully qualified domain name using the host and domain name of the cluster device
instead of the outside IP address when redirecting VPN client connections to that cluster device.