<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need to Reload Primary Core ASA in HA cluster without causing downtime in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690501#M191555</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a clusted set of ASA 5520's in my data center, and I need to reload the primary unit asap without causing downtime.&lt;/P&gt;&lt;P&gt;Is there a way I can fail-over to the standby ASA 5520 in the cluster (with no interruption), issue a command to reload the primary unit, then fail back to primary once it is up, all without causing any downtime at any part of the process?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:56:17 GMT</pubDate>
    <dc:creator>Dean Romanelli</dc:creator>
    <dc:date>2019-03-12T05:56:17Z</dc:date>
    <item>
      <title>Need to Reload Primary Core ASA in HA cluster without causing downtime</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690501#M191555</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a clusted set of ASA 5520's in my data center, and I need to reload the primary unit asap without causing downtime.&lt;/P&gt;&lt;P&gt;Is there a way I can fail-over to the standby ASA 5520 in the cluster (with no interruption), issue a command to reload the primary unit, then fail back to primary once it is up, all without causing any downtime at any part of the process?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690501#M191555</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2019-03-12T05:56:17Z</dc:date>
    </item>
    <item>
      <title>Make sure your in active</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690502#M191556</link>
      <description>&lt;P&gt;Make sure your in active/standby mode between the 2 ASAs , check the show failover is set correctly , if thats setup then you will only drop a couple of pings the failover is very quick , dropped my primary earlier to update the ios had a constant ping running was maybe 1-2 second drop , no users even noticed it but your config needs to be correct&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 14:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690502#M191556</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2015-05-14T14:40:05Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,Thanks. After review</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690503#M191557</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;Thanks. After review I believe it is set up correctly, but another set of eyes wouldn't hurt. Here is the existing config (I didn't set this up personally). If you would, could you have a look?&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface failover Management0/0&lt;BR /&gt;failover mac address GigabitEthernet0/0 0000.0100.0001 0000.0100.0002&lt;BR /&gt;failover mac address GigabitEthernet0/1 0000.0100.0011 0000.0100.0012&lt;BR /&gt;failover mac address GigabitEthernet0/2 0000.0100.0021 0000.0100.0022&lt;BR /&gt;failover link statefailover GigabitEthernet0/3&lt;BR /&gt;failover interface ip failover 1.1.1.1 255.255.255.252 standby 1.1.1.2&lt;BR /&gt;failover interface ip statefailover 1.1.1.5 255.255.255.252 standby 1.1.1.6&lt;/P&gt;&lt;P&gt;FWCore-INET5520# show fail&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: failover Management0/0 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 3 of 160 maximum&lt;BR /&gt;Version: Ours 9.1(5)21, Mate 9.1(5)21&lt;BR /&gt;Last Failover at: 20:25:37 GMT/BST Jan 21 2015&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This host: Primary - Active&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 9745642 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5520 hw/sw rev (2.0/9.1(5)21) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (109.xxx.xxx.164): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (192.168.123.2): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (192.168.122.1): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: ASA-SSM-10 hw/sw rev (1.0/7.0(7)E4) status (Unresponsive/Up)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.0(7)E4, Not Applicable&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Other host: Secondary - Standby Ready&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 373 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5520 hw/sw rev (2.0/9.1(5)21) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (-INET-GW): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (192.168.123.3): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (192.168.122.2): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: ASA-SSM-10 hw/sw rev (1.0/7.0(7)E4) status (Unresponsive/Up)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.0(7)E4, Not Applicable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 14:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690503#M191557</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2015-05-14T14:58:07Z</dc:date>
    </item>
    <item>
      <title>Yes thats looks good , the fw</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690504#M191558</link>
      <description>&lt;P&gt;Yes thats looks good , the fw your on is the&amp;nbsp;primary and its active and the secondary is ready to take over&lt;/P&gt;&lt;P&gt;When you issue reload the ASA will fail to the secondary&amp;nbsp;192.168.123.3 fw ,&amp;nbsp; make sure to save your config 1st just in case&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;This host: Primary - Active&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 9745642 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5520 hw/sw rev (2.0/9.1(5)21) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (109.xxx.xxx.164): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (192.168.123.2): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (192.168.122.1): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: ASA-SSM-10 hw/sw rev (1.0/7.0(7)E4) status (Unresponsive/Up)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.0(7)E4, Not Applicable&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;Other host: Secondary - Standby Ready&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 373 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5520 hw/sw rev (2.0/9.1(5)21) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (-INET-GW): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (192.168.123.3): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (192.168.122.2): Normal (Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: ASA-SSM-10 hw/sw rev (1.0/7.0(7)E4) status (Unresponsive/Up)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.0(7)E4, Not Applicable&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 15:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690504#M191558</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2015-05-14T15:03:00Z</dc:date>
    </item>
    <item>
      <title>Thanks again Mark.So just to</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690505#M191560</link>
      <description>&lt;P&gt;Thanks again Mark.&lt;/P&gt;&lt;P&gt;So just to confirm, all I need to do is type "reload" while on the primary firewall and it will failover?&lt;/P&gt;&lt;P&gt;I don't need to manually fail myself over to secondary and then reload primary from there?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 16:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690505#M191560</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2015-05-14T16:17:30Z</dc:date>
    </item>
    <item>
      <title>Yes exactly when you do that</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690506#M191562</link>
      <description>&lt;P&gt;Yes exactly when you do that if you log into the 2nd firewall currently the backup you will see it has become the primary active and the asa you just set to reload becomes standby ready , you would then reload again on the current primary which was originally your backup to flip it back, it's a bit confusing but there is logic behind it just keep checking your show fail over outputs to confirm it's worked &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 16:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690506#M191562</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2015-05-14T16:37:38Z</dc:date>
    </item>
    <item>
      <title>Thanks Mark.</title>
      <link>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690507#M191565</link>
      <description>&lt;P&gt;Thanks Mark.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 18:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-reload-primary-core-asa-in-ha-cluster-without-causing/m-p/2690507#M191565</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2015-05-14T18:11:26Z</dc:date>
    </item>
  </channel>
</rss>

