<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replace a Failed Firepower Appliance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639419#M1091312</link>
    <description>&lt;P&gt;hi rk,&lt;/P&gt;&lt;P&gt;since you've got a case opened with TAC, why don't you ask for their guidance/document/best practice directly from them?&lt;/P&gt;&lt;P&gt;this is what you've paid for.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jun 2022 10:12:56 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2022-06-27T10:12:56Z</dc:date>
    <item>
      <title>Replace a Failed Firepower Appliance</title>
      <link>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639411#M1091311</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some guidance on how to replace a failed Firepower Appliance. There is ton's of information on cisco.com for this but none of them provides a step by step procedure as we generally would find in the case of routers/switches etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So here it goes, we have two Firepower 4100s on our network which run an ASA as a logical appliance, the two ASAs form an HA pair. One of the Firepowers has failed and Cisco TAC have confirmed that the device need to be replaced.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I am very new to these devices, it will great if the experts here can guide me to some documentation which can help with swapping the device without resulting an an outage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 09:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639411#M1091311</guid>
      <dc:creator>rkAtCisco</dc:creator>
      <dc:date>2022-06-27T09:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Replace a Failed Firepower Appliance</title>
      <link>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639419#M1091312</link>
      <description>&lt;P&gt;hi rk,&lt;/P&gt;&lt;P&gt;since you've got a case opened with TAC, why don't you ask for their guidance/document/best practice directly from them?&lt;/P&gt;&lt;P&gt;this is what you've paid for.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 10:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639419#M1091312</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-06-27T10:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Replace a Failed Firepower Appliance</title>
      <link>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639421#M1091313</link>
      <description>&lt;P&gt;Hello johnlloyd_13,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did, the issue is I have not received a response from Cisco TAC yet which I am happy with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Historically, I have been able to get better solutions here rather than from Cisco TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 10:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4639421#M1091313</guid>
      <dc:creator>rkAtCisco</dc:creator>
      <dc:date>2022-06-27T10:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Replace a Failed Firepower Appliance</title>
      <link>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4640113#M1091371</link>
      <description>&lt;P&gt;Well there really isn't much to it since these are in an HA setup.&amp;nbsp; Here is a walkthrough from the FTD7.1 configuration guide&lt;/P&gt;
&lt;TABLE class="stepTable" border="0" width="998px"&gt;
&lt;TBODY&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;1&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;If the unit you are replacing is functional, ensure that you fail over to the peer unit, then use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;shutdown&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;command from the device CLI to bring down the device gracefully. If the unit is not functional, confirm that the peer is operating in Active mode.&lt;/P&gt;
&lt;SECTION class="itemgroup info"&gt;
&lt;P class="p"&gt;If you have Administrator privileges, you can also enter the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;shutdown&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;command through the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;FDM&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;CLI Console.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;2&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;Remove the unit from the network.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;3&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;Install the replacement unit and reconnect the interfaces.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;4&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;Complete the device setup wizard on the replacement unit.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;5&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;On the peer unit, go to the High Availability page and copy the configuration to the clipboard. Note whether the unit is the Primary or the Secondary unit.&lt;/P&gt;
&lt;SECTION class="itemgroup info"&gt;
&lt;P class="p"&gt;If there are any pending changes, deploy them now and wait for deployment to complete before continuing.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;6&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;On the replacement unit, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Configure&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;group, then select the opposite unit type from the peer. That is, if the peer is primary, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Secondary&lt;/SPAN&gt;, if the peer is secondary, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Primary&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="li step"&gt;
&lt;TD width="99.9375px" align="left" valign="top"&gt;&lt;STRONG&gt;Step&amp;nbsp;7&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="897.062px" align="left" valign="top"&gt;
&lt;P class="ph cmd"&gt;Paste in the HA configuration from the peer, then enter the IPsec key if you use one. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Activate HA&lt;/SPAN&gt;.&lt;/P&gt;
&lt;SECTION class="itemgroup info"&gt;
&lt;P class="p"&gt;Once deployment is complete, the unit will contact the peer and join the HA group. The active peer's configuration will be imported, and the replacement unit will be either the primary or secondary unit in the group, based on your selection. You can now verify that HA is operating correctly, and if desired, switch modes so that the new unit is the active unit.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/710/fdm/fptd-fdm-config-guide-710/fptd-fdm-ha.html#id_72193" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/710/fdm/fptd-fdm-config-guide-710/fptd-fdm-ha.html#id_72193&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 08:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-a-failed-firepower-appliance/m-p/4640113#M1091371</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-28T08:43:23Z</dc:date>
    </item>
  </channel>
</rss>

