<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active/Standby ASA Failover Config Changes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-config-changes/m-p/1692995#M562219</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 ASA 5540s ver 8.3 in Active/Standby state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am considering a future hypothetical situation where I might need to rename interfaces or reallocate redundant interface groups.&amp;nbsp; Doing so obviously has a major impact on the current primary configuration.&amp;nbsp; My goal would be to minimize or eliminate network downtime during the interface changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if it is possible to force the secondary ASA from the standby to active state.&lt;/P&gt;&lt;P&gt;Then temporarily disable failover on the primary unit.&lt;/P&gt;&lt;P&gt;Make the interface changes on the primary unit&lt;/P&gt;&lt;P&gt;Then reactivate failover on the primary unit&lt;/P&gt;&lt;P&gt;Force the primary unit back to active and secondary unit to standby&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My new interface configuration would then sync from the primary to the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe this would work but must ensure that the secondary ASA can function as the active unit while the failover is disabled on the primary unit.&amp;nbsp; Is there a set length of time the secondary unit can remain active without a failover peer? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone see issues with operating the secondary unit in this manner while making changes to the primary unit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:34:11 GMT</pubDate>
    <dc:creator>Cody Ridge</dc:creator>
    <dc:date>2019-03-11T20:34:11Z</dc:date>
    <item>
      <title>Active/Standby ASA Failover Config Changes</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-config-changes/m-p/1692995#M562219</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 ASA 5540s ver 8.3 in Active/Standby state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am considering a future hypothetical situation where I might need to rename interfaces or reallocate redundant interface groups.&amp;nbsp; Doing so obviously has a major impact on the current primary configuration.&amp;nbsp; My goal would be to minimize or eliminate network downtime during the interface changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if it is possible to force the secondary ASA from the standby to active state.&lt;/P&gt;&lt;P&gt;Then temporarily disable failover on the primary unit.&lt;/P&gt;&lt;P&gt;Make the interface changes on the primary unit&lt;/P&gt;&lt;P&gt;Then reactivate failover on the primary unit&lt;/P&gt;&lt;P&gt;Force the primary unit back to active and secondary unit to standby&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My new interface configuration would then sync from the primary to the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe this would work but must ensure that the secondary ASA can function as the active unit while the failover is disabled on the primary unit.&amp;nbsp; Is there a set length of time the secondary unit can remain active without a failover peer? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone see issues with operating the secondary unit in this manner while making changes to the primary unit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-config-changes/m-p/1692995#M562219</guid>
      <dc:creator>Cody Ridge</dc:creator>
      <dc:date>2019-03-11T20:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Standby ASA Failover Config Changes</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-asa-failover-config-changes/m-p/1692996#M562220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the right way to do, the trAffic would pass normally through the secondary firewall so don't worry about it, thats the whole purpose of failover on ASA. The secondary would keep passing the traffic normally until it is active, there is no time limit to it. As far as your question regarding minimizing the downtime is concerned, I suggest you have a look at the virtual mac-address configuration and stateful configuration in failover. Here is the doc for it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Stateful failover -----&amp;gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Virtual mac-address-------&amp;gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/asa/asa83/command/reference/m.html#wp2111374"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa83/command/reference/m.html#wp2111374&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 16:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-asa-failover-config-changes/m-p/1692996#M562220</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-16T16:39:18Z</dc:date>
    </item>
  </channel>
</rss>

