<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert single Firepower 1120 into an HA pair in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5196553#M1115940</link>
    <description>&lt;P&gt;First i would Draw a diagram that includes cables and Layer2 to connection to switch.&lt;/P&gt;
&lt;P&gt;I would go simple steps :&lt;/P&gt;
&lt;P&gt;1. take the configuration backup from exiting firewall and write the configuration on the Live one.&lt;/P&gt;
&lt;P&gt;2. New one upgrade the ASA code as same old one same, Make sure both same model and same code on both device.&lt;/P&gt;
&lt;P&gt;3. Configure the Interface and HA Links and switch configuration.&lt;/P&gt;
&lt;P&gt;Follow below guide lines :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa919/configuration/general/asa-919-general-config/ha-failover.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa919/configuration/general/asa-919-general-config/ha-failover.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;some example configuration you can follow :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.packetswitch.co.uk/cisco-asa-active-passive-failover-example/" target="_blank"&gt;https://www.packetswitch.co.uk/cisco-asa-active-passive-failover-example/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Note : before enable failover - check you have reachability between HA Link p2p IP ( so you are sure the connection reachable)&lt;/P&gt;
&lt;P&gt;If all&amp;nbsp; good then when you enable failover on both unit you see below message as mentioned in the document :&lt;/P&gt;
&lt;H4 id="ariaid-title32" class="title topictitle4"&gt;Running Configuration Replication&lt;/H4&gt;
&lt;P&gt;&lt;SPAN&gt;Beginning configuration replication: Sending to mate,” and when it is complete, the ASA displays the message “End Configuration Replication to mate.” Depending on the size of the configuration, replication can take from a few seconds to several minutes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2024 18:40:34 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-09-19T18:40:34Z</dc:date>
    <item>
      <title>Convert single Firepower 1120 into an HA pair</title>
      <link>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5196536#M1115939</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a single Firepower 1120 running ASA software which is currently in production and working fine. It has been decided to add a second 1120 and convert them into an HA pair running as active/standby for redundancy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone advise if there is an established process for doing this when one of the firewalls is already live, and would it be possible to achieve without any downtime?&amp;nbsp;&amp;nbsp;The traffic volume is low and it only has a handful of firewall and NAT rules, no VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 18:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5196536#M1115939</guid>
      <dc:creator>graham robinson</dc:creator>
      <dc:date>2024-09-19T18:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Convert single Firepower 1120 into an HA pair</title>
      <link>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5196553#M1115940</link>
      <description>&lt;P&gt;First i would Draw a diagram that includes cables and Layer2 to connection to switch.&lt;/P&gt;
&lt;P&gt;I would go simple steps :&lt;/P&gt;
&lt;P&gt;1. take the configuration backup from exiting firewall and write the configuration on the Live one.&lt;/P&gt;
&lt;P&gt;2. New one upgrade the ASA code as same old one same, Make sure both same model and same code on both device.&lt;/P&gt;
&lt;P&gt;3. Configure the Interface and HA Links and switch configuration.&lt;/P&gt;
&lt;P&gt;Follow below guide lines :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa919/configuration/general/asa-919-general-config/ha-failover.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa919/configuration/general/asa-919-general-config/ha-failover.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;some example configuration you can follow :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.packetswitch.co.uk/cisco-asa-active-passive-failover-example/" target="_blank"&gt;https://www.packetswitch.co.uk/cisco-asa-active-passive-failover-example/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Note : before enable failover - check you have reachability between HA Link p2p IP ( so you are sure the connection reachable)&lt;/P&gt;
&lt;P&gt;If all&amp;nbsp; good then when you enable failover on both unit you see below message as mentioned in the document :&lt;/P&gt;
&lt;H4 id="ariaid-title32" class="title topictitle4"&gt;Running Configuration Replication&lt;/H4&gt;
&lt;P&gt;&lt;SPAN&gt;Beginning configuration replication: Sending to mate,” and when it is complete, the ASA displays the message “End Configuration Replication to mate.” Depending on the size of the configuration, replication can take from a few seconds to several minutes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 18:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5196553#M1115940</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-09-19T18:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Convert single Firepower 1120 into an HA pair</title>
      <link>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5199269#M1116069</link>
      <description>&lt;P&gt;Thanks, I followed the guidelines and was able to convert the single unit into an HA pair.&lt;/P&gt;&lt;P&gt;There was an outage of about 30secs after entering the "failover" command on the active unit whilst it negotiated with the new unit and then applied the active config again, but that's fine.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 09:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/convert-single-firepower-1120-into-an-ha-pair/m-p/5199269#M1116069</guid>
      <dc:creator>graham robinson</dc:creator>
      <dc:date>2024-09-26T09:02:58Z</dc:date>
    </item>
  </channel>
</rss>

