nerdexam
Cisco

300-320 · Question #259

When a Cisco ASA adaptive security appliance is configured for active/standby failover, which MAC address is used for the active unit?

The correct answer is A. the MAC address of the primary unit. In Cisco ASA active/standby failover, the active unit uses its own physical MAC address (the primary unit's MAC). This is by design: when the primary unit is active, it operates normally with its own MAC. If a failover occurs and the standby (secondary) unit takes over, it…

Security Services

Question

When a Cisco ASA adaptive security appliance is configured for active/standby failover, which MAC address is used for the active unit?

Options

  • Athe MAC address of the primary unit
  • Bthe MAC address of the secondary unit
  • Cthe virtual MAC address
  • Dthe standby MAC address

How the community answered

(55 responses)
  • A
    89% (49)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (4)

Explanation

In Cisco ASA active/standby failover, the active unit uses its own physical MAC address (the primary unit's MAC). This is by design: when the primary unit is active, it operates normally with its own MAC. If a failover occurs and the standby (secondary) unit takes over, it adopts the primary unit's MAC address. This MAC address takeover is critical because it prevents connected devices (upstream/downstream switches and routers) from needing to update their ARP tables - they continue sending traffic to the same MAC address, and the secondary unit now receives it. There is no 'virtual MAC' used by default in active/standby mode (unlike some HSRP/VRRP implementations), though Cisco ASA does support configured virtual MAC addresses as an optional feature.

Topics

#ASA failover#active/standby#MAC address#firewall high availability

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice