<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM Upgrade for ASA Active/ Active in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451924#M67164</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The AIPs are independent of the ASA failover, however, the ASA can consider the AIP status in failover switchover, meaning it can failover&lt;/P&gt;&lt;P&gt; if it detects an AIP module going down on the active device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best method for upgrade in this situation will be to setup active failover status for all groups on the primary ASA, then upgrade the AIP of the secondary ASA.&lt;/P&gt;&lt;P&gt;Once the AIP of the secondary is completely updated and functional, then set all the groups to be active failover on the secondary ASA.&lt;/P&gt;&lt;P&gt;Then upgrade the Primary AIP.&lt;/P&gt;&lt;P&gt;Once the primary AIP is completely upgraded and working, you can then restore the failover status on the ASAs, by setting failover active for the group on the specific ASAs you want them to be active on..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 19 Jun 2010 23:50:32 GMT</pubDate>
    <dc:creator>edadios</dc:creator>
    <dc:date>2010-06-19T23:50:32Z</dc:date>
    <item>
      <title>AIP-SSM Upgrade for ASA Active/ Active</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451923#M67163</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;I&amp;nbsp; need some help on upgrading the aip-ssm modules to E4 on two asa s which are active/active state. Will i be able to do this without the downtime?what are considerations ?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451923#M67163</guid>
      <dc:creator>Nandan Mathure</dc:creator>
      <dc:date>2019-03-10T12:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM Upgrade for ASA Active/ Active</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451924#M67164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The AIPs are independent of the ASA failover, however, the ASA can consider the AIP status in failover switchover, meaning it can failover&lt;/P&gt;&lt;P&gt; if it detects an AIP module going down on the active device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best method for upgrade in this situation will be to setup active failover status for all groups on the primary ASA, then upgrade the AIP of the secondary ASA.&lt;/P&gt;&lt;P&gt;Once the AIP of the secondary is completely updated and functional, then set all the groups to be active failover on the secondary ASA.&lt;/P&gt;&lt;P&gt;Then upgrade the Primary AIP.&lt;/P&gt;&lt;P&gt;Once the primary AIP is completely upgraded and working, you can then restore the failover status on the ASAs, by setting failover active for the group on the specific ASAs you want them to be active on..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jun 2010 23:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451924#M67164</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-06-19T23:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM Upgrade for ASA Active/ Active</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451925#M67165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will go with what you say. Thanks for your time &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nandan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Jun 2010 19:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451925#M67165</guid>
      <dc:creator>Nandan Mathure</dc:creator>
      <dc:date>2010-06-20T19:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM Upgrade for ASA Active/ Active</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451926#M67166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you also have to do this everytime you push a sig update to the AIP's as well?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 18:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451926#M67166</guid>
      <dc:creator>mkirbyii</dc:creator>
      <dc:date>2010-06-25T18:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM Upgrade for ASA Active/ Active</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451927#M67167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In general a signature update does not require a reload. So you can independently do signature updates on the modules on each of the pair, and not be concerned about triggering&amp;nbsp; failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may help clarify what you want to avoid doing if you don't want failover to happen in relation to the modules on ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp5355853"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp5355853&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jun 2010 05:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-upgrade-for-asa-active-active/m-p/1451927#M67167</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-06-26T05:01:23Z</dc:date>
    </item>
  </channel>
</rss>

