1-13
Cisco ASA Series CLI Configuration Guide
Chapter 1 Setting General VPN Parameters
Configuring Load Balancing
For example, to assign this device a NAT address of 192.168.30.3 and 2001:DB8::1, enter the following
command:
hostname(config-load-balancing)#
nat 192.168.30.3 2001:DB8::1
hostname(config-load-balancing)#
Configuring the Load Balancing Cluster Attributes
To configure the load-balancing cluster attributes for each device in the cluster, do the following steps:
Step 1
Set up VPN load balancing by entering the
vpn load-balancing
command in global configuration mode:
hostname(config)#
vpn load-balancing
hostname(config-load-balancing)#
This enters vpn-load-balancing configuration mode, in which you can configure the remaining
load-balancing attributes.
Step 2
Configure the IP address or the fully qualified domain name of the cluster to which this device belongs.
This command specifies the single IP address or FQDN that represents the entire virtual cluster. Choose
an IP address that is within the public subnet address range shared by all the ASAs in the virtual cluster.
You can specify an IPv4 or IPv6 address.
hostname(config-load-balancing)#
cluster ip address
ip_address
hostname(config-load-balancing)#
For example, to set the cluster IP address to IPv6 address, 2001:DB8::1, enter the following command:
hostname(config-load-balancing)#
cluster ip address 2001:DB8::1
hostname(config-load-balancing)#
Step 3
Configure the cluster port. This command specifies the UDP port for the virtual cluster in which this
device is participating. The default value is 9023. If another application is using this port, enter the UDP
destination port number that you want to use for load balancing.
hostname(config-load-balancing)#
cluster port
port_number
hostname(config-load-balancing)#
For example, to set the cluster port to 4444, enter the following command:
hostname(config-load-balancing)#
cluster port 4444
hostname(config-load-balancing)#
Step 4
(Optional) Enable IPsec encryption for the cluster. The default is no encryption. This command enables
or disables IPsec encryption. If you configure this check attribute, you must first specify and verify a
shared secret.The ASAs in the virtual cluster communicate via LAN-to-LAN tunnels using IPsec. To
ensure that all load-balancing information communicated between the devices is encrypted, enable this
attribute.
hostname(config-load-balancing)#
cluster encryption
hostname(config-load-balancing)#
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......