<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Procedure for Swapping out live firewalls in a failover pair in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3823531#M950228</link>
    <description>&lt;P&gt;Thanks for your help,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Brian&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2019 10:47:36 GMT</pubDate>
    <dc:creator>bbriggs</dc:creator>
    <dc:date>2019-03-21T10:47:36Z</dc:date>
    <item>
      <title>Procedure for Swapping out live firewalls in a failover pair</title>
      <link>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3696404#M950215</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a task to swap-out &amp;nbsp;two ASA single-mode firewalls.&lt;/P&gt;
&lt;P&gt;They are in a pair and neither has failed, this is merely a hardware upgrade.&lt;/P&gt;
&lt;P&gt;I am tempted to failover i.e. enter "no failover active" and replace the Primary unit first.&lt;/P&gt;
&lt;P&gt;However if I left the HA pair in their current configuration and replaced the Secondary, without failing over, the Primary should be able to keep working.&lt;/P&gt;
&lt;P&gt;The firewalls should then sync from Primary to Secondary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once I replace the Primary I can then failover by entering "no failover active" and then replace the Secondary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is anyone aware of an official procedure to replace a failover pair where both are working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3696404#M950215</guid>
      <dc:creator>bbriggs</dc:creator>
      <dc:date>2020-02-21T16:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Procedure for Swapping out live firewalls in a failover pair</title>
      <link>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3696553#M950221</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As long as the hardware model is same, you can do what you have described. Going by the description, looks like you are doing a hardware upgrade, which means at one point of time primary and secondary firewalls will be different models. That is not supported for a failover replacement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best way for hardware upgrade would be to take a maintenance window and do it. Should not take more time. We can prepare a parallel setup and swap the firewalls out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the model is same, then you can follow the steps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/introducing-failed-primary-unit-back-in-the-ha-fail-over-pair/ta-p/3146927" target="_blank"&gt;https://community.cisco.com/t5/security-documents/introducing-failed-primary-unit-back-in-the-ha-fail-over-pair/ta-p/3146927&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 20:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3696553#M950221</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-08-28T20:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Procedure for Swapping out live firewalls in a failover pair</title>
      <link>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3823531#M950228</link>
      <description>&lt;P&gt;Thanks for your help,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 10:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/procedure-for-swapping-out-live-firewalls-in-a-failover-pair/m-p/3823531#M950228</guid>
      <dc:creator>bbriggs</dc:creator>
      <dc:date>2019-03-21T10:47:36Z</dc:date>
    </item>
  </channel>
</rss>

