<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA failover commands in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003330#M400753</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a pair of ASAs, one of which I need to move. For that I would like to turn off failover to be on the safe side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turning it off is described everywhere, but not how to turn it back on correctly (so that configs will sync again etc.).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, how would I proceed for the entire process?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- First, I check if the one I'd like to remain in production is active. (If not I make it active using "failover active")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Second, I say 'no failover' and this will have been the last command that will be issued automatically to both cluster members, and no automatic failover will occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Then, I do whatever I have to do with the standby cluster member.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When I'm finished, I do what exactly? Just say "failover" again to enable it? On both devices? (since both devices are not in sync anymore)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marki&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:43:00 GMT</pubDate>
    <dc:creator>jer0nim0x</dc:creator>
    <dc:date>2019-03-11T23:43:00Z</dc:date>
    <item>
      <title>ASA failover commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003330#M400753</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a pair of ASAs, one of which I need to move. For that I would like to turn off failover to be on the safe side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turning it off is described everywhere, but not how to turn it back on correctly (so that configs will sync again etc.).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, how would I proceed for the entire process?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- First, I check if the one I'd like to remain in production is active. (If not I make it active using "failover active")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Second, I say 'no failover' and this will have been the last command that will be issued automatically to both cluster members, and no automatic failover will occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Then, I do whatever I have to do with the standby cluster member.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- When I'm finished, I do what exactly? Just say "failover" again to enable it? On both devices? (since both devices are not in sync anymore)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marki&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003330#M400753</guid>
      <dc:creator>jer0nim0x</dc:creator>
      <dc:date>2019-03-11T23:43:00Z</dc:date>
    </item>
    <item>
      <title>ASA failover commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003331#M400754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't really had to move any firewall equipment in the failover pair but I have had to disconnect a secondary firewall because of a failover related problem (Configuration Sync didnt go through and the Secondary Firewall caused the whole pair to loose connectivity....for some reason).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically what I did in the situation was the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Disconnected the Secondary firewall from the network&lt;/P&gt;&lt;P&gt;- Erased the configurations from the Secondary firewall and reloaded it&lt;/P&gt;&lt;P&gt;- Configured the Secondary firewall with Failover configurations only&lt;/P&gt;&lt;P&gt;- Connected the Secondary firewall back to the network (everything but the actual Failover interface)&lt;/P&gt;&lt;P&gt;- Connected the Secondary firewall to Primary firewall with the failover cable (Actual firewalls located in 2 different datacenters)&lt;/P&gt;&lt;P&gt;- Watched as the Secondary firewall found the Primary firewall and started receiving the configuration from the Primary unit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The failover configuration on the Secondary device is the following (Primary devices configuration only difference is naturally that its defined as &lt;STRONG&gt;primary&lt;/STRONG&gt; unit)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover lan unit secondary&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover lan interface failover GigabitEthernet0/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover key &lt;KEY&gt;&lt;/KEY&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover link failover GigabitEthernet0/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover interface ip failover x.x.x.x 255.255.255.252 standby y.y.y.y&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 10:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003331#M400754</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-08-16T10:04:03Z</dc:date>
    </item>
    <item>
      <title>ASA failover commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003332#M400755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is exactly the thing I'd like to do (move one ASA to other datacenter)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disconnecting the sync is not the hard part. The ASAs won't bother (active remains active, standby remains standby)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when the secondary's sync link goes back up (and suppose the sync transit network is not correctly configured) it won't see the primary, it will go active and we'll have a split brain scenario which I'd like to avoid...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 11:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-commands/m-p/2003332#M400755</guid>
      <dc:creator>jer0nim0x</dc:creator>
      <dc:date>2012-08-16T11:48:50Z</dc:date>
    </item>
  </channel>
</rss>

