<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413212#M806773</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow this link, am sure you wont have any problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Dec 2009 06:09:45 GMT</pubDate>
    <dc:creator>Parminder Sian</dc:creator>
    <dc:date>2009-12-18T06:09:45Z</dc:date>
    <item>
      <title>ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413210#M806771</link>
      <description>&lt;P&gt;I plan to deploy a second ASA soon and i want to make sure there won't be a service outage on my Active ASA. So, does anyone know if there will be an outage on my Primary ASA when i add the standby config and connect my secondary ASA? We have several site to site VPNs that i can't drop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413210#M806771</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2019-03-11T16:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413211#M806772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;cowetacoit wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plan to deploy a second ASA soon and i want to make sure there won't be a service outage on my Active ASA. So, does anyone know if there will be an outage on my Primary ASA when i add the standby config and connect my secondary ASA? We have several site to site VPNs that i can't drop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be no outage as long as you configure it correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 00:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413211#M806772</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-12-18T00:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413212#M806773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow this link, am sure you wont have any problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 06:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413212#M806773</guid>
      <dc:creator>Parminder Sian</dc:creator>
      <dc:date>2009-12-18T06:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413213#M806774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds good, thanks. I've already built my config so it should work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 13:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413213#M806774</guid>
      <dc:creator>cowetacoit</dc:creator>
      <dc:date>2009-12-18T13:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413214#M806775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As other said, you shouldnt have issues here.. but have console on your failover when you do this change.. sometimes when you do a wr standby you might have to enable the "failvoer" configuration manually on secondary firewall , to bring the failover up.. i faced issues when bringing failover sometime back and had to manually do it thro console.. also, even though it might not affect, I would think you take atleast a 30 min downtime, to make sure your production traffic is not affected ! better to take a downtime , rather than being on priority 1 calls &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the best&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 16:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413214#M806775</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2009-12-18T16:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413215#M806776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed on the downtime, rather i call it maintenence window:)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding to above, it takes around 2-4 minutes for active ASA to replicate the config (depending on the size) to the secondary, so, "show failover" might show you the peer not connected during that. Connecting console to the right box is the key &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 16:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413215#M806776</guid>
      <dc:creator>mohsin.khan</dc:creator>
      <dc:date>2009-12-21T16:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413216#M806777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mohsin,&lt;/P&gt;&lt;P&gt;Primary and Secondary are the units designation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active and Standby are the roles that they take/play.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A Primary unit can be active or standby&lt;/P&gt;&lt;P&gt;A Secondary unit can be standby or active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It takes a while to get used to the terminology.&amp;nbsp; I had a hard time too when I first started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, when the primary unit is active (with the failover lines in the config and failover enabled) you are wanted to add the secondary unit as standby correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow these steps.&lt;/P&gt;&lt;P&gt;1. Copy and paste the output of "sh run fail" - from the Primary/active unit on notepad&lt;/P&gt;&lt;P&gt;2. Then change the "failover lan unit primary" to "failover lan unit secondary".&lt;/P&gt;&lt;P&gt;3. Now copy all the lines to the secondary unit except the "failover" part - leave it out.&lt;/P&gt;&lt;P&gt;4. Issue "sh run fail" in both units -make sure one says primary and the other says secondary&lt;/P&gt;&lt;P&gt;5. Then issue "sh fail" on the primary - make sure it says "this unit active" "other unit failed"&lt;/P&gt;&lt;P&gt;6. Then enable "failover" in the standby unit&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;7. watch it detect an active mate and sync up.&lt;/P&gt;&lt;P&gt;8. once done verify "sh fail" output in both units.&lt;/P&gt;&lt;P&gt;On the primary you will see this unit active other unit standby ready&lt;/P&gt;&lt;P&gt;on the secondary unit will see this unit standby other unit active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 18:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/1413216#M806777</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-21T18:29:32Z</dc:date>
    </item>
  </channel>
</rss>

