3-10
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 3 Managing the Device Inventory
Adding Devices to the Device Inventory
Unsupported Features on ASA Clusters
These features cannot be configured with clustering enabled, and the commands will be rejected.
• Unified Communications
• Remote access VPN (SSL VPN and IPsec VPN)
• The following application inspections:
–
CTIQBE
–
GTP
–
H323, H225, and RAS
–
IPsec passthrough
–
MGCP
–
MMP
–
RTSP
–
SIP
–
SCCP (Skinny)
–
WAAS
–
WCCP
• Botnet Traffic Filter
• Auto Update Server
• DHCP client, server, relay, and proxy
• VPN load balancing
• Failover
• ASA CX module
Centralized Features
The following features are only supported on the master unit, and are not scaled for the cluster. For
example, you have a cluster of eight units (5585-X with SSP-60). The Other VPN license allows a
maximum of 10,000 IPsec tunnels for one ASA 5585-X with SSP-60. For the entire cluster of eight units,
you can only use 10,000 tunnels; the feature does not scale.
Note Traffic for centralized features is forwarded from member units to the master unit over the cluster
control link; see the "Sizing the Cluster Control Link" section to ensure adequate bandwidth for the
cluster control link. If you use the rebalancing feature (see the "Rebalancing New TCP Connections
Across the Cluster" section), traffic for centralized features may be rebalanced to non-master units
before the traffic is classified as a centralized feature; if this occurs, the traffic is then sent back to the
master unit. For centralized features, if the master unit fails, all connections are dropped, and you have
to re-establish the connections on the new master unit.
• Site-to-site VPN
• The following application inspections:
–
DCERPC
–
NetBios
–
PPTP
–
RADIUS