<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Urgent. need to do on firday night.. IPS shutdown please rea in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123529#M54128</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jcarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Yea i finished my work that day. on ASA 1 IPS module was unresponsive and couldn’t shut it down. then i powered off IPS and removed card on ASA2 shut down the IPS module and then physically removed card then failover start working again,. Thanks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Client wanted to test failover. I removed WAN cable from ASA1 then traffic moved to ASA2 after around 8 packet drops. but when i plugged back WAN cable on ASA1 traffic didn’t move back to ASA1 from ASA2. Then i removed cable from ASA2 WAN and traffic moved to ASA1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i thought it should reverse back to primary device once primary device is in stable and healthy state. it mean we have to do manual failover from secondary to primary. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Feb 2013 18:24:39 GMT</pubDate>
    <dc:creator>Tarjeet Singh</dc:creator>
    <dc:date>2013-02-04T18:24:39Z</dc:date>
    <item>
      <title>Urgent. need to do on firday night.. IPS shutdown please read n comment</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123524#M54123</link>
      <description>&lt;P&gt;My client has active (ASA1)/passive (ASA2) firewalls 5520 both firewalls have IPS ASA-SSM-20… On Active (ASA1) Firewall IPS module failed and failover method found ASA1 is unhealthy because IPS is failed and Failover switched over to Standby ASA2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Yes we need to replace ASA1 IPS to bring back failover to ASA1.. But my client doesn’t want to buy new one..&amp;nbsp; So he requested me to take out secondary ASA2 IPS. So ASA2 will switch back to ASA1 once Failover will find out that there is no more IPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me, How I can remove IPS from ASA2 which is Active now. So failover switch back to ASA1 Active. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I just shut down IPS on both routers so failover method will not check for IPS &lt;/P&gt;&lt;P&gt; hw-module module 1 shutdown&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123524#M54123</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2019-03-10T12:53:16Z</dc:date>
    </item>
    <item>
      <title>Urgent. need to do on firday night.. IPS shutdown please read n</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123525#M54124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just read that you can &lt;SPAN style="font-size: 10pt;"&gt;remove the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Modular Policy Framework configuration &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;that forwards traffic down to the AIP, which will disassociate the AIP's availability from the failover mechanism. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;So when i will remove &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Modular Policy Framework configuration &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;from ASA1 and ASA2 then i just have to reset ASA1 and failover will ignore IPS and consider ASA1 as healthy and ASA1 will be active again. then i wont be using IPS. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 23:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123525#M54124</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2013-01-31T23:24:18Z</dc:date>
    </item>
    <item>
      <title>Urgent. need to do on firday night.. IPS shutdown please read n</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123526#M54125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tarjeet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the end whether you are using the AIP-SSM module or not they are required hardware for failover to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That means that if you take the AIP-SSM module of one and try to work with that it will not run as the hardware will not match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I will recommend you first of all taking the policy-action of sending the traffic to the AIP-SSM on both devices ( Active/standby)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then shut it down and remove it from active ( the one that is already failed) then turn it down on the secondary and remove it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Afterwards with both ASA's with no AIP-SSM their status will change to UP as they do not see any internal/external hardware failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2013 23:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123526#M54125</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-02-02T23:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent. need to do on firday night.. IPS shutdown please rea</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123527#M54126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi Jcarvaja,&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;&amp;nbsp;&amp;nbsp; Thank you very much for replying. I have rescheduled this work for today 9:00 PST. I was actually planning to just remove module policy work config from both ASA 1 &amp;amp; 2, I thought failover will work after that. But now I understand that we do need to remove AIP module from both ASA 1 &amp;amp; 2 because hardware will not match. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;On my ASA1 AIP is in unresponsive mode. I can’t shutdown or reset. So I will just remove policy config and remove AIP physically from ASA1. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;On ASA2 I will shut down AIP module then after that i will remove AIP physically from ASA2. then failover should be fine after that. Please advice.&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;===========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Also I was thinking, if just shutdown AIP on ASA2 and remove policy config from both ASA then failover should work because AIP will be still physically present in ASA. But problem is one AIP is unresponsive and one will be shutdown. Do you think, it will be fine? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLEASE ADVISE I HAVE 4 HOURS LEFT...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2013 00:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123527#M54126</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2013-02-03T00:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent. need to do on firday night.. IPS shutdown please rea</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123528#M54127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I am late ( More than 4 hours &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0cm 0cm 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;Also I was thinking, if just shutdown AIP on ASA2 and remove policy config from both ASA then failover should work because AIP will be still physically present in ASA. But problem is one AIP is unresponsive and one will be shutdown. Do you think, it will be fine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do that, it will still do not work because it will determine that one is failed and the other one is just shut-down ( manually)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the way to go is the one you said previously:&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0cm 0cm 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;On my ASA1 AIP is in unresponsive mode. I can’t shutdown or reset. So I will just remove policy config and remove AIP physically from ASA1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0cm 0cm 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;On ASA2 I will shut down AIP module then after that i will remove AIP physically from ASA2. then failover should be fine after that. Please advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share with us the result and some kudos lol&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2013 07:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123528#M54127</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-02-03T07:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent. need to do on firday night.. IPS shutdown please rea</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123529#M54128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jcarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Yea i finished my work that day. on ASA 1 IPS module was unresponsive and couldn’t shut it down. then i powered off IPS and removed card on ASA2 shut down the IPS module and then physically removed card then failover start working again,. Thanks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Client wanted to test failover. I removed WAN cable from ASA1 then traffic moved to ASA2 after around 8 packet drops. but when i plugged back WAN cable on ASA1 traffic didn’t move back to ASA1 from ASA2. Then i removed cable from ASA2 WAN and traffic moved to ASA1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i thought it should reverse back to primary device once primary device is in stable and healthy state. it mean we have to do manual failover from secondary to primary. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 18:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123529#M54128</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2013-02-04T18:24:39Z</dc:date>
    </item>
    <item>
      <title>Urgent. need to do on firday night.. IPS shutdown please read n</title>
      <link>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123530#M54129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tarjeet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know that I could help &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; ( Please remember to rate all of the posts, so we can know that we indeed help)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now regarding the last question you are talking about preemption and on the ASA that is only supported for active/active failover, that means that on active/standby failover a automatic failover because of the detection of the primary unit will not happen unless the secondary fails..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that I could help with all of my explanations,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to rate all of the helpful posts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal&lt;/P&gt;&lt;P&gt;Security Trainer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 02:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/urgent-need-to-do-on-firday-night-ips-shutdown-please-read-n/m-p/2123530#M54129</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-02-08T02:44:35Z</dc:date>
    </item>
  </channel>
</rss>

