<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: make secondary ASA the new Primary and active asa in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3409161#M237073</link>
    <description>&lt;P&gt;Propagation of configuration changes is always from Active to Standby.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whether a unit is Primary or Secondary has nothing to do with that bit - it's strictly a convention to distinguish one appliance from the other.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jul 2018 15:39:40 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-07-02T15:39:40Z</dc:date>
    <item>
      <title>make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/2551598#M237064</link>
      <description>&lt;P style="outline: none; margin: 0px 0px 10px; color: rgb(51, 51, 51); font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;We have two cisco asa 5510's in a failover setup.&lt;/P&gt;&lt;P style="outline: none; margin: 0px 0px 10px; color: rgb(51, 51, 51); font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;I'd like to take the secondary/failover and make it the primary/active and do this for good..not just for testing. And of course make the other the new secondary/failover.&lt;/P&gt;&lt;P style="outline: none; margin: 0px 0px 10px; color: rgb(51, 51, 51); font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;What would be the best way of doing this? What config do I need to change?&lt;/P&gt;&lt;P style="outline: none; margin: 0px 0px 10px; color: rgb(51, 51, 51); font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;"&gt;To sum it up, Id like to swap the units from primary to secondary and vice versa.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:23:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/2551598#M237064</guid>
      <dc:creator>ellbom101</dc:creator>
      <dc:date>2019-03-12T04:23:53Z</dc:date>
    </item>
    <item>
      <title>Just issue the command "no</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/2551599#M237065</link>
      <description>&lt;P&gt;Just issue the command "no failover active" on the primary ASA.&amp;nbsp; The secondary unit will now be the primary/active unit and will remain that way until another failover situation occurs.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2014 10:18:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/2551599#M237065</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-29T10:18:22Z</dc:date>
    </item>
    <item>
      <title>hi,marius is correct.you</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/2551600#M237067</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;marius is correct.&lt;/P&gt;&lt;P&gt;you could alternatively do this via ASDM.&lt;/P&gt;&lt;P&gt;click on &lt;STRONG&gt;Make Standby&lt;/STRONG&gt; button.&lt;/P&gt;&lt;P&gt;see screenshot attached.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 08:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/2551600#M237067</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2014-06-30T08:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: hi,marius is correct.you</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3184170#M237068</link>
      <description>&lt;P&gt;Primary will be always primary and secondary will be always secondary.., only you can change the Active and standby mode. after putting "failover active" on standby unit, it will become Secondary/Active and other will be primary/Standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saurabh&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 14:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3184170#M237068</guid>
      <dc:creator>Saurabh_Srivastava</dc:creator>
      <dc:date>2017-09-14T14:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3184200#M237069</link>
      <description>&lt;P&gt;Is you want to change the role and not just the state, you will need to make the failover unit Secondary-Active as others have described. Then take the Primary-Standby offline. Modify the Secondary-Active configuration to designate it as Primary and the (offline) Primary unit to make it Secondary. Then bring the former Primary (newly designated Secondary) back online.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bigger question is why go the the trouble? The designation is purely cosmetic in 99% of the use cases.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 15:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3184200#M237069</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-09-14T15:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3336430#M237070</link>
      <description>Can you elaborate all the steps that you have describe?</description>
      <pubDate>Fri, 23 Feb 2018 06:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3336430#M237070</guid>
      <dc:creator>plongba278</dc:creator>
      <dc:date>2018-02-23T06:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3336478#M237071</link>
      <description>&lt;P&gt;I suggest you start a new thread and describe what you're trying to accomplish.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 08:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3336478#M237071</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-02-23T08:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3409085#M237072</link>
      <description>Sorry, old post, but just wanted to thank Marvin and post another follow-up question to his response.  &lt;BR /&gt;&lt;BR /&gt;I believe you're correct, and that Marius was missing those last steps(as his would only change from active/standby, and not the primary/secondary).  However, you mentioned it was mostly cosmetic.  So, are you saying I can make changes to the config on my secondary, and it will push those changes out to the primary as well?  All changes don't have to go through the primary to propagate to the secondary?</description>
      <pubDate>Mon, 02 Jul 2018 14:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3409085#M237072</guid>
      <dc:creator>dsanchez81</dc:creator>
      <dc:date>2018-07-02T14:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3409161#M237073</link>
      <description>&lt;P&gt;Propagation of configuration changes is always from Active to Standby.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whether a unit is Primary or Secondary has nothing to do with that bit - it's strictly a convention to distinguish one appliance from the other.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 15:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3409161#M237073</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-07-02T15:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3677448#M237074</link>
      <description>&lt;P&gt;I have a similar scenario.&amp;nbsp; The&amp;nbsp;Secondary is Active.&amp;nbsp; The Primary is offline and out of sync with the Secondary.&amp;nbsp; I want to make change my Secondary to Primary, wipe my old Primary and make it Secondary.&amp;nbsp; The process appears easy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question&amp;nbsp;is when I change my current Secondary/Active to Primary/Active&amp;nbsp;via:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;failover lan unit primary&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;will this cause any downtime?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 13:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3677448#M237074</guid>
      <dc:creator>NeverOutofTune</dc:creator>
      <dc:date>2018-07-30T13:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: hi,marius is correct.you</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3892218#M237075</link>
      <description>&lt;P&gt;Thank you Marius. It was a pretty easy fix.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 19:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/3892218#M237075</guid>
      <dc:creator>jca_connecticut@hotmail.com</dc:creator>
      <dc:date>2019-07-17T19:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/4723803#M1095149</link>
      <description>&lt;P&gt;hi marvin,&lt;/P&gt;&lt;P&gt;i have the same scenario wherein i needed to reverse the primary and secondary role.&lt;/P&gt;&lt;P&gt;when you say take the primary-standby offline, do you mean disable failover/sync using the 'no failover' command?&lt;/P&gt;&lt;P&gt;does it need to be applied on both ASA or just the primary-standby?&lt;/P&gt;&lt;P&gt;can i just straight away reverse role without disabling failover/sync? it's just less than of a second to apply in CLI.&lt;/P&gt;&lt;P&gt;will there be an issue if both secondary-active and primary-standby FW temporarily have the "failover lan unit primary"?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 13:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/4723803#M1095149</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-11-18T13:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/4723851#M1095150</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt; I'm not sure if your suggested method would work. It shouldn't hurt to try but I'd hesitate to do so in production.&lt;/P&gt;
&lt;P&gt;My suggestion for taking primary-standby offline was to take it truly offline - disconnect or shutdown its data interfaces. Then modify the secondary-active with the "failover lan unit primary". Similarly modify the offline unit with "failover lan unit secondary". Then bring it back online.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 14:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/4723851#M1095150</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-11-18T14:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: make secondary ASA the new Primary and active asa</title>
      <link>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/4724194#M1095161</link>
      <description>&lt;P&gt;hi marvin,&lt;/P&gt;&lt;P&gt;thanks! just to be in the safe side, i will do this in a change window and disable failover between the two before changing/reverse the primary and secondary role.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2022 00:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-secondary-asa-the-new-primary-and-active-asa/m-p/4724194#M1095161</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-11-19T00:28:12Z</dc:date>
    </item>
  </channel>
</rss>

