<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FMC/FTD Breaking HA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4469881#M1083831</link>
    <description>&lt;P&gt;Hi Sam,&lt;/P&gt;&lt;P&gt;Since you'll be using same device, I believe you don't need to hardcode MAC address this time, however, I would still advise it. This time you will just reimage device, but next time it might be HW replacement.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
    <pubDate>Mon, 20 Sep 2021 05:46:46 GMT</pubDate>
    <dc:creator>Milos_Jovanovic</dc:creator>
    <dc:date>2021-09-20T05:46:46Z</dc:date>
    <item>
      <title>Cisco FMC/FTD Breaking HA</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4468749#M1083789</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a Cisco vFMC with two Cisco Firepower configured as HA pair. At present the Secondary unit is Active. We got an issue with the Primary unit and have to perform factory-reset. I got a couple of questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Do I have to break the HA configuration first and then reset the unit? Or I can perform a reset while the HA configuration is intact.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) If I have to break the HA configuration (while the Secondary unit is Active), what will happen? Does the Secondary Active unit continue to function without any disruption?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope someone can help me with this issue. Any suggestion or advice will be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards &amp;amp; Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 19:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4468749#M1083789</guid>
      <dc:creator>IamSamSaul</dc:creator>
      <dc:date>2021-09-17T19:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD Breaking HA</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4468783#M1083795</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/879593"&gt;@IamSamSaul&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you have backup of your FTD device, then follow the guielines from &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/backup_and_restore.html#Cisco_Task.dita_a44c742a-9670-4b54-b792-6ba3a3133133" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;If you don't have backup, then you can find guidelines &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/high_availability_for_firepower_threat_defense.html#id_14945" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;One note - I always like to hardcode MAC addresses because of this, as in HA, primary device is providing MAC address for active unit. If replaced, new primary unit will provide new MAC address, which can cause interruptions. For this reason, I always hardcode them, so I don't really care which unit is primary, as no physcal addresses are in use. I would advise to configure currently active MAC as primary before you proceed with rebuilding units (although I'm not sure you would be able to deploy new policy while one device is down).&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 20:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4468783#M1083795</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-09-17T20:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD Breaking HA</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4468917#M1083799</link>
      <description>Hi Milos,&lt;BR /&gt;&lt;BR /&gt;Thanks for your reply.&lt;BR /&gt;&lt;BR /&gt;I don't have the latest backup. I'm not going to replace the unit. After&lt;BR /&gt;upgrading the unit I can't log into the cli. I read that I have to factory&lt;BR /&gt;reset the unit. Do I still have to hard code the MAC address because it&lt;BR /&gt;will be the same unit?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Sam&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Sep 2021 21:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4468917#M1083799</guid>
      <dc:creator>IamSamSaul</dc:creator>
      <dc:date>2021-09-17T21:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD Breaking HA</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4469881#M1083831</link>
      <description>&lt;P&gt;Hi Sam,&lt;/P&gt;&lt;P&gt;Since you'll be using same device, I believe you don't need to hardcode MAC address this time, however, I would still advise it. This time you will just reimage device, but next time it might be HW replacement.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 05:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4469881#M1083831</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-09-20T05:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC/FTD Breaking HA</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4489512#M1084520</link>
      <description>&lt;P&gt;Hi Milos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing the same problem on Device1. Can you describe the steps you used to fix the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description of my case:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have two Cisco Firepower 2110 in HA Configuration. I tried to perform version upgrade from 6.4. to 6.6. I got Device2 (Standbyd device) upgraded to 6.6. But the Device1 (Primary) failed the update. And the Device1 i showing up in maintenance mode after i manually rebooted Device1 after upgrade failure. I cannot access the device using SSH. I can ping the management IP.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 22:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-ftd-breaking-ha/m-p/4489512#M1084520</guid>
      <dc:creator>vashan</dc:creator>
      <dc:date>2021-10-20T22:17:03Z</dc:date>
    </item>
  </channel>
</rss>

