<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:ASA 5525x active actulive issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054441#M398447</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is for the security ela license for 2000 firewalls, that enables the ips modules and other features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found two issues but worked through them, both involved the standby asa: first issue was with the ssh keys dissappearing, second was in the method your provided, when re-enabling failover the standby asa would recalculate its virtual mac address and not send a garp to update to the upstream router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ended up finding out that the activation key command is not replicated, so we activated the pair through the active asa, "activation-key", then "failover exec mate activation key" to update the standby. We ran a script and it worked on all the asas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Oct 2012 18:49:48 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-10-08T18:49:48Z</dc:date>
    <item>
      <title>ASA 5525x active actulive issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054439#M398445</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a mass licensing project where I have to upgrade activation keys on over 2000 asas in active active mode. When disabling failover on the active I have noticed 2 issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first issue is that the "pseudo-standby" asa destroys its current contexts after I re-enable failover on the primary. This causes all the secondary contexts to recalculate their virtual macs which causes arp issues and with my luck the uplink is a bvi with the default arp timeout set to 4 hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second issue is that all the rsa keys are destroyed when the xontexts are regenerated and I have to re issue the crypto key gen......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are these two bugs and should the contexts be updated and not dropped and recreated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054439#M398445</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2019-03-12T00:02:07Z</dc:date>
    </item>
    <item>
      <title>ASA 5525x active actulive issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054440#M398446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What license is this? Does it require reload or not?&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa81/license/license81.html#wp51459"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/license/license81.html#wp51459&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. check if this procedure will work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 18:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054440#M398446</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2012-10-08T18:35:29Z</dc:date>
    </item>
    <item>
      <title>Re:ASA 5525x active actulive issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054441#M398447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is for the security ela license for 2000 firewalls, that enables the ips modules and other features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found two issues but worked through them, both involved the standby asa: first issue was with the ssh keys dissappearing, second was in the method your provided, when re-enabling failover the standby asa would recalculate its virtual mac address and not send a garp to update to the upstream router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ended up finding out that the activation key command is not replicated, so we activated the pair through the active asa, "activation-key", then "failover exec mate activation key" to update the standby. We ran a script and it worked on all the asas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 18:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-active-actulive-issues/m-p/2054441#M398447</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-08T18:49:48Z</dc:date>
    </item>
  </channel>
</rss>

