<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change ASA Active-Standby Primary and Secondary role in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717952#M1094859</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt; so you are physically moving the hardware of the "primary/active" ASA to another building?&lt;/P&gt;
&lt;P&gt;If so you could unplug the primary ASA, failover would automatically occur to the secondary ASA. At which point change the configuration to primary (of the new active/primary ASA). Move the ASA hardware, before you re-plug into the network, set it as secondary. Once connected they should reconnect as a failover pair.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2022 14:10:24 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-11-08T14:10:24Z</dc:date>
    <item>
      <title>Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717934#M1094857</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i got a pair of ASA FW in active-standby setup each in a different building.&lt;/P&gt;&lt;P&gt;we're closing one of the building/rack and plan is to bring the primary-active FW to the next building where secondary-standby FW is installed.&lt;/P&gt;&lt;P&gt;is there a "safe" way of changing the primary-active FW to secondary and secondary-standby FW to primary and make it active?&lt;/P&gt;&lt;P&gt;do i disable failover in each ASA FW using a &lt;STRONG&gt;no failover&lt;/STRONG&gt; command and change role with &lt;STRONG&gt;failover lan unit &amp;lt;primary/secondary&amp;gt;&lt;/STRONG&gt; command? or do i just straight away change the role?&lt;/P&gt;&lt;P&gt;or is there an order to follow, i.e. force a failover primary-active &amp;gt; secondary-standby, disable failover, change secondary ASA to primary and lastly change primary ASA to secondary?&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;failover&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;EM&gt;failover lan unit &lt;FONT color="#FF0000"&gt;primary&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;failover lan interface FAILOVER GigabitEthernet0/7&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;failover key *****&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;failover replication http&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;failover link FAILOVER GigabitEthernet0/7&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;failover interface ip FAILOVER 192.168.1.1 255.255.255.252 standby 192.168.1.2&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 13:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717934#M1094857</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-11-08T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717939#M1094858</link>
      <description>&lt;P&gt;Sure if the Active standby configured as per the best practice :&lt;/P&gt;
&lt;P&gt;"no failover active" on Primary ASA - that will bring&amp;nbsp; secondary unit will now be the primary/active unit.&lt;/P&gt;
&lt;P&gt;Once you bring back Primary in to the respected place, if you like you can failover.&lt;/P&gt;
&lt;P&gt;no need to change the roles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 13:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717939#M1094858</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-08T13:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717952#M1094859</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt; so you are physically moving the hardware of the "primary/active" ASA to another building?&lt;/P&gt;
&lt;P&gt;If so you could unplug the primary ASA, failover would automatically occur to the secondary ASA. At which point change the configuration to primary (of the new active/primary ASA). Move the ASA hardware, before you re-plug into the network, set it as secondary. Once connected they should reconnect as a failover pair.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 14:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717952#M1094859</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-08T14:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717985#M1094862</link>
      <description>&lt;P&gt;Changing the roles is not necessary and I would not recommend it as it would mean breaking and rebuilding the HA setup.&amp;nbsp; Safest is to manually issue the command "failover active" on the standby device or "no failover active" on the primary and then remove the Primary-Standby device from the network and move it to the it's new location and plug it back into the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A failover back to the Primary-Standby would need to be done manually if you want it to be the active firewall as the current active will not give up the active role automatically.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 14:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4717985#M1094862</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-11-08T14:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718396#M1094904</link>
      <description>&lt;P&gt;hi rob,&lt;/P&gt;&lt;P&gt;yes, i'm going to physical move the primary-active ASA FW to the next building where the secondary-standby ASA FW is installed.&lt;/P&gt;&lt;P&gt;i want to force changing of role by making the secondary-standby ASA FW as the primary-active while the former primary-active is power off and waiting to be installed/cabled.&lt;/P&gt;&lt;P&gt;can you confirm if my thought process is correct:&lt;/P&gt;&lt;P&gt;force a failover primary-active &amp;gt; secondary-standby, disable failover, change secondary ASA to primary and lastly change primary ASA to secondary?&lt;/P&gt;&lt;P&gt;or is there a step i missed or anything to add?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 02:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718396#M1094904</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-11-09T02:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718501#M1094914</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt; yes, just ensure you've made the configuration changes to the old primary before physically reconnecting and attempt to establish communication with the new primary/active. And obviously ensure you've L2 connectivity.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 08:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718501#M1094914</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-09T08:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718537#M1094921</link>
      <description>&lt;P&gt;Be careful when changing the failover configuration on the Secondary device.&amp;nbsp; I would recommend the following steps for the move and do the configuration change in a service window:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Take a complete backup of the ASA configuration&lt;/LI&gt;
&lt;LI&gt;Failover from Primary to Secondary (so that secondary is the active ASA)&lt;/LI&gt;
&lt;LI&gt;Remove Primary (standby) device from the network&lt;/LI&gt;
&lt;LI&gt;Move the Primary (standby) device to new location (&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;do not connect to the network yet&lt;/STRONG&gt;&lt;/FONT&gt;)&lt;/LI&gt;
&lt;LI&gt;Clear the configuration on Primary (standby) and configure failover and set device to be Secondary&lt;/LI&gt;
&lt;LI&gt;Change the Secondary (active) failover configuration to be Primary (&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;I recommend doing this via console access&lt;/FONT&gt;&lt;/STRONG&gt;)&lt;/LI&gt;
&lt;LI&gt;Connect the new Secondary (standby) device to the network as well as failover and state link to the new Primary (active) device&lt;/LI&gt;
&lt;LI&gt;Verify that configuration is synchronised to the new Secondary (standby device)&lt;/LI&gt;
&lt;LI&gt;Perform a failover so that the new Secondary device becomes active and verify that traffic flows successfully through it without issues (Test failover)&lt;/LI&gt;
&lt;LI&gt;Failover back to the Primary device&lt;/LI&gt;
&lt;LI&gt;Be sure that configuration is saved&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 09 Nov 2022 09:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718537#M1094921</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-11-09T09:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718547#M1094925</link>
      <description>&lt;P&gt;hi marius,&lt;/P&gt;&lt;P&gt;i'm going to do this remotely before we disconnect the initial primary-active and relocate to the next DC.&lt;/P&gt;&lt;P&gt;can't i just straight away reverse the ASA role secondary &amp;gt; primary and vice versa without clear config and disconnect the former primary-active ASA?&lt;/P&gt;&lt;P&gt;or maybe issue a "no failover" so the two ASA won't talk to each other while changing their roles?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 10:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718547#M1094925</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-11-09T10:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Change ASA Active-Standby Primary and Secondary role</title>
      <link>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718559#M1094927</link>
      <description>&lt;P&gt;The problem with the no failover command on a secondary device is that all configuration will be removed from the device.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am uncertain of changing the role from Secondary to Primary and how this will affect the configuration as I have not tested this.&amp;nbsp; This is why I have suggested the steps in my previous post.&lt;/P&gt;
&lt;P&gt;If you will be remote and someone else will be physically moving the devices I would recommend that they have a PC ready and a console cable / mini USB cable so that you can connect to the devices if you should lose connectivity to them.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 10:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-asa-active-standby-primary-and-secondary-role/m-p/4718559#M1094927</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-11-09T10:37:39Z</dc:date>
    </item>
  </channel>
</rss>

