300-710 · Question #44
What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?
The correct answer is C. VPN connections must be re-established when a new master unit is elected.. In a Cisco ASA or FTD cluster, VPN sessions are anchored to the control (master) unit. Unlike stateful failover in active/standby pairs, clusters do not fully synchronize VPN session state across all data units. When a new control unit is elected-due to the current master failing
Question
What is the disadvantage of setting up a site-to-site VPN in a clustered-units environment?
Options
- AVPN connections can be re-established only if the failed master unit recovers.
- BSmart License is required to maintain VPN connections simultaneously across all cluster units.
- CVPN connections must be re-established when a new master unit is elected.
- DOnly established VPN connections are maintained when a new master unit is elected.
How the community answered
(27 responses)- B4% (1)
- C93% (25)
- D4% (1)
Explanation
In a Cisco ASA or FTD cluster, VPN sessions are anchored to the control (master) unit. Unlike stateful failover in active/standby pairs, clusters do not fully synchronize VPN session state across all data units. When a new control unit is elected-due to the current master failing or being removed-all active site-to-site VPN tunnels must be torn down and re-negotiated from scratch. This is a known architectural limitation of clustering with VPN: it does not provide seamless VPN failover. Option A is incorrect because connections do not recover only when the old master returns; a new master can be elected from any surviving unit. Option B is incorrect because Smart Licensing is unrelated to VPN session continuity. Option D is incorrect because established sessions are not preserved when a new master is elected-they must be re-established.
Topics
Community Discussion
No community discussion yet for this question.