<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby' in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056631#M1068552</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Once the Active/Standby process is done, you should be able to SSH into both, assuming you generated RSA keys on both, as these are not synchronised.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;In general, there is no real need to SSH into the second device, you can send commands to the standby ASA via "failover exec" commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2020 10:17:14 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2020-04-01T10:17:14Z</dc:date>
    <item>
      <title>Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056609#M1068549</link>
      <description>&lt;P&gt;&lt;FONT color="#58585b"&gt;&lt;FONT face="CiscoSans, Arial, sans-serif"&gt;&lt;FONT size="3"&gt;Hello,&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#58585b"&gt;&lt;FONT face="CiscoSans, Arial, sans-serif"&gt;&lt;FONT size="3"&gt;I have a Cisco ASA configuration&amp;nbsp;: HA- Active/Standby.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#58585b"&gt;&lt;FONT face="CiscoSans, Arial, sans-serif"&gt;&lt;FONT size="3"&gt;As soon as I set up standby, I lose the ssh connection. This is because the management interface is overwritten by the synchronization of the configuration with the 'Active'.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#58585b"&gt;&lt;FONT face="CiscoSans, Arial, sans-serif"&gt;&lt;FONT size="3"&gt;Can you help me, please?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 09:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056609#M1068549</guid>
      <dc:creator>bcr</dc:creator>
      <dc:date>2020-04-01T09:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056624#M1068551</link>
      <description>&lt;P&gt;as soon as you failover to stanby you lost the connection to ssh. if so that is normal behaviour as the mac adresses reason.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 10:04:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056624#M1068551</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-04-01T10:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056631#M1068552</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Once the Active/Standby process is done, you should be able to SSH into both, assuming you generated RSA keys on both, as these are not synchronised.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;In general, there is no real need to SSH into the second device, you can send commands to the standby ASA via "failover exec" commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 10:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056631#M1068552</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-01T10:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056635#M1068554</link>
      <description>&lt;P&gt;In Active/standby failover the active device uses the primary unit MAC addresses. In the event of failover the secondary appliance becomes active and takes over the primary unit MAC addreses. whereas the active device now standby takes over the standby unit MAC addresses. After the standby appliance become active, it sends out a gratuitous ARP on ther network. A gratuitous ARP is an ARP request that the appliace sends out on the ethernet networks with the source and destination IP Addresses of the active ip addresses. The destination MAC address is the ethernet broadcast address. all devices on ther ethernet segment process this braodcast frmae and update the their arp table with this information. using gratuittous arp the layer 2 devices including switches also updates the content CAM table with the mac address and updated switch port infirmation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this will you understad whats happening behind the scene.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 10:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056635#M1068554</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-04-01T10:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056638#M1068555</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/295226"&gt;@Cristian Matei&lt;/a&gt;&amp;nbsp;mentioned&amp;nbsp;&lt;SPAN&gt;"failover exec" this is very useful.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;failover exec interface GigabitEthernet0/1&lt;/PRE&gt;
&lt;PRE&gt;failover exec active show failover&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Apr 2020 10:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056638#M1068555</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-04-01T10:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056642#M1068556</link>
      <description>&lt;P&gt;Thank you for the answer on the operating principle.&lt;BR /&gt;In fact, I would like to work in a lab so that I can fully understand how it works.&lt;BR /&gt;I didn't generate any RSA keys. Is there a solution without RSA.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Yours sincerely,&lt;BR /&gt;bcr.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 10:33:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056642#M1068556</guid>
      <dc:creator>bcr</dc:creator>
      <dc:date>2020-04-01T10:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056652#M1068560</link>
      <description>&lt;P&gt;you could be using the default RSA key in ASA. as long as you have ASA connection via SSH it mean you have RSA keys either custom defined or system defined.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please do not forget to rate the post as it will help other engineers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 10:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4056652#M1068560</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-04-01T10:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA : HA- Active/Standby. ssh connection problem with 'Standby'</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4057054#M1068602</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;BR /&gt;&lt;BR /&gt;I tried using a unique RSA key on ASA1 and ASA2 and it works.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Can you tell me the source of cisco information on this problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cordially,&lt;BR /&gt;bcr.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 18:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-active-standby-ssh-connection-problem-with-standby/m-p/4057054#M1068602</guid>
      <dc:creator>bcr</dc:creator>
      <dc:date>2020-04-01T18:34:39Z</dc:date>
    </item>
  </channel>
</rss>

