<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Active/Standby failover pair. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-pair/m-p/1728366#M557859</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have two 5540's in an Active/Standby pair. The primary unit failed on February 12th, so the secondary ASA is now the active one. My question is this - we have made a lot of changes since February 12th and I am planning on fixing this failover issue over the weekend. Will the secondary (now active) FW sync it's config to the non-active FW, or will the failed FW sync it's out-of-date config - removing any changes that we've made in the last month or so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you. &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:21:03 GMT</pubDate>
    <dc:creator>jasonb77</dc:creator>
    <dc:date>2019-03-11T20:21:03Z</dc:date>
    <item>
      <title>ASA Active/Standby failover pair.</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-pair/m-p/1728366#M557859</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have two 5540's in an Active/Standby pair. The primary unit failed on February 12th, so the secondary ASA is now the active one. My question is this - we have made a lot of changes since February 12th and I am planning on fixing this failover issue over the weekend. Will the secondary (now active) FW sync it's config to the non-active FW, or will the failed FW sync it's out-of-date config - removing any changes that we've made in the last month or so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover-pair/m-p/1728366#M557859</guid>
      <dc:creator>jasonb77</dc:creator>
      <dc:date>2019-03-11T20:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby failover pair.</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-pair/m-p/1728367#M557861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be fine. The Active ASA should always perform the synch to the standaby ASA (your old primary unit). I've done this on numerous occasions and never had an issue with it. However just to be certain I would also back up your running config as well. If you want to ensure that you get VPN preshared keys do a "write net" to an external TFTP Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Barry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 16:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover-pair/m-p/1728367#M557861</guid>
      <dc:creator>barry</dc:creator>
      <dc:date>2011-04-14T16:47:55Z</dc:date>
    </item>
  </channel>
</rss>

