<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failover Questions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064685#M399586</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Varun!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Sep 2012 14:48:41 GMT</pubDate>
    <dc:creator>CSCO11733516</dc:creator>
    <dc:date>2012-09-10T14:48:41Z</dc:date>
    <item>
      <title>Failover Questions</title>
      <link>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064683#M399584</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Just doing some studying and running into something that I am not quiete understanding...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If i have 2 firewall's in Active/Active Stateful failover mode and 2 contexts (E1 and E2).&amp;nbsp; Let's say ASA1 has E1 as the active context and ASA2 has E2 as the active context.&amp;nbsp; E2 is the only context used to connect Router_X.&amp;nbsp; If I need to permit traffic to Router_X, would I make the ACL in the ASA1 E2 context (secondary) or in the ASA2 E2 context (primary)?&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;I completed an Active\Active Statuful failover configuration between 2 firewalls, but once I was finished I remembered that i didn't configure the failover group 2 as secondary (problem).&amp;nbsp; So i went ahead and make the configuration change, once I did so I entered the commands NO FAILOVER/FAILOVER to "resynch" the configurations between the 2 firewalls.&amp;nbsp; Is this necessary or couldn't I just perform a WRITE on the primary ASA?&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Is there any command that will verify that each of the configurations on both firewalls are syncrhonized?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ahead of time guys!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064683#M399584</guid>
      <dc:creator>CSCO11733516</dc:creator>
      <dc:date>2019-03-11T23:51:53Z</dc:date>
    </item>
    <item>
      <title>Failover Questions</title>
      <link>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064684#M399585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kenneth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are your answers:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. If you need to make changes, always do that on the active context, replication is always done from active to standby, so you need to make changes on E2 active context on ASA2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You need not do this everytime, just do a write mem or write standby, that would save teh configuration on the standby context as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. There is no command to verify the command replication, you can check the status of the contexts through "show failover" in the system context, if they show active and standby, then everything is fine. You can study different failovers status's from here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s3_72.html#wp1285409"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s3_72.html#wp1285409&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 03:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064684#M399585</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-10T03:24:44Z</dc:date>
    </item>
    <item>
      <title>Failover Questions</title>
      <link>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064685#M399586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Varun!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 14:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-questions/m-p/2064685#M399586</guid>
      <dc:creator>CSCO11733516</dc:creator>
      <dc:date>2012-09-10T14:48:41Z</dc:date>
    </item>
  </channel>
</rss>

