<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA failover pair: ¿does IDS module´s config get replicated? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090686#M393404</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding in an ASA failover setup the configurations are only replicated between the ASA configurations and no module configurations are replicated and need to be manually configured to match on both units.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one Cisco document quote regarding ASA module configuration replication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;If you have two ASAs in a failover configuration and each has an &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AIP-SSM, you &lt;STRONG&gt;must&lt;/STRONG&gt; manually replicate the configuration of the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AIP-SSMs. Only the configuration of the ASA is replicated by the failover &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;mechanism.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 05 Jan 2013 12:12:14 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-01-05T12:12:14Z</dc:date>
    <item>
      <title>ASA failover pair: ¿does IDS module´s config get replicated?</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090685#M393403</link>
      <description>&lt;P&gt;hello team, I am seeking for help in regards to an unanswered question that I posted in the IDS thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: let´s suppose that I execute a basic setup (admin username/password, IP address, mask, gateway, NTP), on the IPS module of the active ASA firewall. ¿Will this configuration be replicated to the IPS module of the secondary unit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your kind answer will be greatly appreciated.&lt;/P&gt;&lt;P&gt;Best regards...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090685#M393403</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2019-03-12T00:43:29Z</dc:date>
    </item>
    <item>
      <title>ASA failover pair: ¿does IDS module´s config get replicated?</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090686#M393404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding in an ASA failover setup the configurations are only replicated between the ASA configurations and no module configurations are replicated and need to be manually configured to match on both units.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one Cisco document quote regarding ASA module configuration replication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;If you have two ASAs in a failover configuration and each has an &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AIP-SSM, you &lt;STRONG&gt;must&lt;/STRONG&gt; manually replicate the configuration of the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AIP-SSMs. Only the configuration of the ASA is replicated by the failover &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;mechanism.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2013 12:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090686#M393404</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-05T12:12:14Z</dc:date>
    </item>
    <item>
      <title>Re:ASA failover pair: ¿does IDS module´s config get replicated</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090687#M393405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does not replicate. Use IME or CSM to manage multiple IPS modules&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2013 16:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090687#M393405</guid>
      <dc:creator>mdreelan</dc:creator>
      <dc:date>2013-01-05T16:36:03Z</dc:date>
    </item>
    <item>
      <title>ASA failover pair: ¿does IDS module´s config get replicated?</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090688#M393406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not only that the config is not replicated, the IPS-modules are "ships in the night". They don't know anything about the other. The second module also doesn't know what the first has already inspected. But that will normally not cause any trouble as the normalizer is not running on the IPS-module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2013 17:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090688#M393406</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-05T17:15:26Z</dc:date>
    </item>
    <item>
      <title>ASA failover pair: ¿does IDS module´s config get replicated?</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090689#M393407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the recommended practice should point to identify each IPS module with its own hostname and management IP address. &lt;/P&gt;&lt;P&gt;Thank you everyone for your kind answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rogelio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2013 22:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090689#M393407</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2013-01-05T22:20:16Z</dc:date>
    </item>
    <item>
      <title>ASA failover pair: ¿does IDS module´s config get replicated?</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090690#M393408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;So the recommended practice should point to identify each IPS module with its own hostname and management IP address.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The hostname is only locally significant, but for clearity they should be different. But each module needs a unique management-adress to reach the GUI and the remote-CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jan 2013 00:36:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090690#M393408</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-06T00:36:10Z</dc:date>
    </item>
    <item>
      <title>ASA failover pair: ¿does IDS module´s config get replicated?</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090691#M393409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, you have to behave as if these are two totally independent devices and configure and manage them seperately. There are a few settings that you can push out to both with IME but I'm not sure it's worth the trouble as there is still a _lot_ that you will have to duplicate on both manually. We're still working on how to reconcile reporting from these things. Also, if one of them crashes for no reason (it happens), the ASA pair will fail over to the one with the functioning IPS. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2013 23:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-pair-does-ids-module-s-config-get-replicated/m-p/2090691#M393409</guid>
      <dc:creator>grahamt</dc:creator>
      <dc:date>2013-01-07T23:04:30Z</dc:date>
    </item>
  </channel>
</rss>

