cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
487
Views
0
Helpful
2
Replies

SSM-10 upgrade in Failover ASA (Active/Standby)

Anuar Shahrin
Level 1
Level 1

Hi,

 

I have an active/standby ASA with both fitted SSM-10. We are planning to do a software upgrade for the SSM-10. My concern here is the proper steps.

Should we start upgrade with the secondary unit first before we perform the upgrade for the Primary? Please advice.

 

Regards,

2 Replies 2

Saurav Lodh
Level 7
Level 7

Yes, when the standby unit has finished reloading, and is in the Standby Ready state, force the active unit to fail over to the standby. Reload the primary with the new image.

rhermes
Level 7
Level 7

It all depends on your Fail Open setting and your security posture.

If your primary ASA is set to Fail Closed, then taking the AIP-SSM off line for an upgrade will cause traffic to fail over to the standby ASA. If you are set for Fail Open then traffic will continue to pass thru your primary ASA without IPS inspection untill the AIP-SSM comes back.

Your security posture will dictate how important IPS inspection/dropping is to your organization. Is mainting IPS inspection more important than failing over to the standby rail?

- Bob

 

Review Cisco Networking products for a $25 gift card