300-320 · Question #259
When a Cisco ASA adaptive security appliance is configured for active/standby failover, which MAC address is used for the active unit?
The correct answer is A. the MAC address of the primary unit. In Cisco ASA active/standby failover, the active unit uses its own physical MAC address (the primary unit's MAC). This is by design: when the primary unit is active, it operates normally with its own MAC. If a failover occurs and the standby (secondary) unit takes over, it…
Question
When a Cisco ASA adaptive security appliance is configured for active/standby failover, which MAC address is used for the active unit?
Options
- Athe MAC address of the primary unit
- Bthe MAC address of the secondary unit
- Cthe virtual MAC address
- Dthe standby MAC address
How the community answered
(55 responses)- A89% (49)
- B2% (1)
- C2% (1)
- D7% (4)
Explanation
In Cisco ASA active/standby failover, the active unit uses its own physical MAC address (the primary unit's MAC). This is by design: when the primary unit is active, it operates normally with its own MAC. If a failover occurs and the standby (secondary) unit takes over, it adopts the primary unit's MAC address. This MAC address takeover is critical because it prevents connected devices (upstream/downstream switches and routers) from needing to update their ARP tables - they continue sending traffic to the same MAC address, and the secondary unit now receives it. There is no 'virtual MAC' used by default in active/standby mode (unlike some HSRP/VRRP implementations), though Cisco ASA does support configured virtual MAC addresses as an optional feature.
Topics
Community Discussion
No community discussion yet for this question.