<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130048#M1072594</link>
    <description>&lt;P&gt;Hey Shawn,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It still not clear to me, in case of the primary having a network failure for instance I understand it moves to fail state, and the secondary node moves from passive to active. But is the config changed and the secondary node becomes primary?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 11:43:25 GMT</pubDate>
    <dc:creator>ThomasCaapiCci</dc:creator>
    <dc:date>2020-08-04T11:43:25Z</dc:date>
    <item>
      <title>ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130014#M1072587</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 ASA 5525 that are setup for failover.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A ASA was always the primary&lt;/P&gt;&lt;P&gt;Site B ASA was always the secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I logged to Site A ASA and noticed the config had changed to secondary.&lt;/P&gt;&lt;P&gt;My first question is: can this happen automatically or do you need to change the config manually for it to happen? In case ASA in Site A would fail, would Site B failover and become primary or would it remain secondary but active?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A ASA config is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface FAILOVER GigabitEthernet0/7&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link FAILOVER GigabitEthernet0/7&lt;BR /&gt;failover interface ip FAILOVER 192.168.255.1 255.255.255.252 standby 192.168.255.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site B ASA config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER GigabitEthernet0/7&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link FAILOVER GigabitEthernet0/7&lt;BR /&gt;failover interface ip FAILOVER 192.168.255.1 255.255.255.252 standby 192.168.255.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My second question is: I want Site A asa to be primary again, how can I do that from the ASDM?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 10:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130014#M1072587</guid>
      <dc:creator>ThomasCaapiCci</dc:creator>
      <dc:date>2020-08-04T10:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130039#M1072590</link>
      <description>&lt;P&gt;1) The failover can occur due to various reasons including but not limited to firewall reboot, interface fail, etc. If any of these reasons occur, then failover automatically occurs.&lt;/P&gt;&lt;P&gt;You can check sh failover history for the reason of failover&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it will be secondary active and primary - failed / standby etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) If you want whatever site to be active, there are two ways&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i) on Active firewall, execute 'no failover active' command&lt;/P&gt;&lt;P&gt;ii) on Standby firewall, execute 'failover active', they both achieve the same purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: You can include failover replication http and&amp;nbsp;failover link failover commands in your failvoer configurutation.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 11:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130039#M1072590</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-08-04T11:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130048#M1072594</link>
      <description>&lt;P&gt;Hey Shawn,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It still not clear to me, in case of the primary having a network failure for instance I understand it moves to fail state, and the secondary node moves from passive to active. But is the config changed and the secondary node becomes primary?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 11:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130048#M1072594</guid>
      <dc:creator>ThomasCaapiCci</dc:creator>
      <dc:date>2020-08-04T11:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130052#M1072595</link>
      <description>&lt;P&gt;The 'Primary' and "Secondary' states will never change, they are hard coded with configuration 'failover lan unit primary' 'failover lan unit seconeary'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only the 'Active' or 'Standby' states change with change in network.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 11:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130052#M1072595</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-08-04T11:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130056#M1072596</link>
      <description>&lt;P&gt;Ah...well then that means someone changed the config, I cant find any other explanation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still want to move the primary to the original ASA, on the ASDM this is the only place I can find that manages primary/secondary settings:&amp;nbsp;&lt;IMG src="https://i.imgur.com/k2NZLS9.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I move the Preferred role to Primary on ASA A so it is set as before and that will take care of it? Should I also set ASA B as preferred secondary? Will the change take care of changing the config?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 12:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130056#M1072596</guid>
      <dc:creator>ThomasCaapiCci</dc:creator>
      <dc:date>2020-08-04T12:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130079#M1072599</link>
      <description>&lt;P&gt;I have not done this myself, but if you have console access to secondary, it's safer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Moving role on Primary for Site A is fine, you should do it if that is how you want it. It will take care on the primary firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you change Site A to primary and see no issues, from CLI on site A, you can execute the following command to change site B to secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;failover exec mate&amp;nbsp;failover lan unit secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 12:40:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130079#M1072599</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-08-04T12:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130100#M1072602</link>
      <description>&lt;P&gt;cheers for that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So on ASA A I issue:&amp;nbsp;&lt;SPAN&gt;failover lan unit primary&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wait a bit (at that point there are 2 primary?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a while on ASA B&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;failover exec mate&amp;nbsp;failover lan unit secondary&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 12:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130100#M1072602</guid>
      <dc:creator>ThomasCaapiCci</dc:creator>
      <dc:date>2020-08-04T12:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130148#M1072609</link>
      <description>&lt;P&gt;Before you do any of this you should break the failover.&amp;nbsp; By issuing the failover lan unit primary on site A you will now have two primary ASAs in the HA setup.&amp;nbsp; When doing this it is best that you have quick access to the console port of both ASAs in case you lose connectivity to the ASAs.&lt;/P&gt;
&lt;P&gt;Here is what I would recommend you do.&lt;/P&gt;
&lt;P&gt;1. make sure Site A is the Active ASA&lt;/P&gt;
&lt;P&gt;2. Remove site B ASA from the network&lt;/P&gt;
&lt;P&gt;3. Change configuration on Site A ASA to be primary&lt;/P&gt;
&lt;P&gt;4. Change configuration on Site B ASA to be secondary&lt;/P&gt;
&lt;P&gt;5. Add Site B ASA back into the network&lt;/P&gt;
&lt;P&gt;6. Force a configuration replication from primary/active to secondary/standby (write standby)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 14:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130148#M1072609</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-08-04T14:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130228#M1072615</link>
      <description>&lt;P&gt;Please follow what Marius said, you need to break the failover, take console of secondary and then make the changes.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 15:48:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-config/m-p/4130228#M1072615</guid>
      <dc:creator>Brad_Shawh</dc:creator>
      <dc:date>2020-08-04T15:48:18Z</dc:date>
    </item>
  </channel>
</rss>

