<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Marvin,Thanks for the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429990#M267438</link>
    <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;When should I have done the 'write standby' command?&lt;/P&gt;&lt;P&gt;Right before connecting the failover link?&lt;/P&gt;&lt;P&gt;Because as soon as I connected the 2 the config sync did take place.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2014 18:08:33 GMT</pubDate>
    <dc:creator>Bram Van den Bosch</dc:creator>
    <dc:date>2014-04-17T18:08:33Z</dc:date>
    <item>
      <title>Replacing dead primary ASA - what did I do wrong</title>
      <link>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429988#M267436</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I faced a problem when replacing a primary ASA with an RMA unit and want to know where I did go wrong.&lt;/P&gt;&lt;P&gt;This is what happened:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The secondary unit was active and had all the config.&lt;/LI&gt;&lt;LI&gt;Installed the new primary unit, configured fail over, connected the fail over interface to the existing secondary ASA.&lt;/LI&gt;&lt;LI&gt;Config synced from the RMA unit to the existing active secondary unit, basically wiped out all the config.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is more detailed info of what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;On the active standby unit, issue the 'no failover' command, followed by the 'failover' command and did a 'write memory'. I wanted to be sure that this is the first unit with the failover command entered, as i found in the documentation that he should then push its config.&lt;/LI&gt;&lt;LI&gt;On the RMA unit: configured failover, configured it as primary.&lt;/LI&gt;&lt;LI&gt;On the RMA unit: added description and 'no shut' command to the failover interface.&lt;/LI&gt;&lt;LI&gt;On the RMA unit: issued the 'failover' command&lt;/LI&gt;&lt;LI&gt;On the RMA unit: issued the 'write memory' command&lt;/LI&gt;&lt;LI&gt;Connected the failover interfaces to each other&lt;/LI&gt;&lt;LI&gt;Then the config synced in the wrong direction, from RMA to active standby unit&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In the end I did fix it with erasing both units, configure failover from scratch and putting back the backup taken before the replacement.&lt;/P&gt;&lt;P&gt;But I want to avoid it in the future!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429988#M267436</guid>
      <dc:creator>Bram Van den Bosch</dc:creator>
      <dc:date>2019-03-12T04:05:39Z</dc:date>
    </item>
    <item>
      <title>You should have done "write</title>
      <link>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429989#M267437</link>
      <description>&lt;P&gt;You should have done "write standby" from the Secondary-Active unit. That would push the proper running config into startup-config on the Primary-Standby unit.&lt;/P&gt;&lt;P&gt;Here's a &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html#pgfId-1155658"&gt;link to the proper section of the Configuration Guide&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 15:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429989#M267437</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-04-17T15:59:06Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,Thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429990#M267438</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;When should I have done the 'write standby' command?&lt;/P&gt;&lt;P&gt;Right before connecting the failover link?&lt;/P&gt;&lt;P&gt;Because as soon as I connected the 2 the config sync did take place.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 18:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429990#M267438</guid>
      <dc:creator>Bram Van den Bosch</dc:creator>
      <dc:date>2014-04-17T18:08:33Z</dc:date>
    </item>
    <item>
      <title>The RMA unit did not need the</title>
      <link>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429991#M267439</link>
      <description>&lt;P&gt;The RMA unit did not need the step 2 "failover primary".&lt;/P&gt;&lt;P&gt;Then, after step 3, you would connect the failover interfaces to each other and the config should have synced in the proper direction (from Secondary - Active to Primary - Standby).&lt;/P&gt;&lt;P&gt;After that was confirmed to happen, you would then issue "write standby" from the Secondary-Active unit.&lt;/P&gt;&lt;P&gt;Finish up with a "failover" from Secondary-Active and you should have the end sate of Primary -Active and Secondary-Standby.&lt;/P&gt;&lt;P&gt;Don't forget to also copy any remote access VPN profiles, ASDM images., certificates, etc. that are outside the configuration but on disk0: and required.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 18:21:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/2429991#M267439</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-04-17T18:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: The RMA unit did not need the</title>
      <link>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/4826417#M1100072</link>
      <description>&lt;P&gt;Just sharing my experience here, but I believe "failover lan unit primary" IS required before configuring failover. I tested this myself, and if you don't configure the device as either primary or secondary, it won't join the failover group.&lt;/P&gt;&lt;P&gt;I believe the one step you missed off, was to disable the production interfaces either by disconnecting the cables or disabling the switch interfaces. I believe this is a CRUCIAL step!&lt;/P&gt;&lt;P&gt;Of course, Cisco could make this far far easier by jus having a failover priority value, like lots of other things do. But that would make everyone's life too easy &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 08:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-dead-primary-asa-what-did-i-do-wrong/m-p/4826417#M1100072</guid>
      <dc:creator>ChrisNewnham_</dc:creator>
      <dc:date>2023-05-02T08:18:21Z</dc:date>
    </item>
  </channel>
</rss>

