04-30-2020 05:35 AM
We have two ASA 5508x that are paired together in a fail over fashion. We what to separate them and use them as two separate firewalls to test if we see a speed increase with a new dedicated Internet line and IP address. How do I that?
Solved! Go to Solution.
04-30-2020 07:43 AM
Perhaps there are aspects of the original post that we do not understand, but it seems a fairly straightforward question. If there is a pair of ASA configured for active/standby failover and you want to use one of the ASA for testing I would suggest these steps:
- identify which ASA is currently the standby unit.
- make a copy of the config of the standby unit.
- disconnect that ASA that is the standby. The unit that is active will continue to be active, will maintain the same configuration, but would not be able to failover.
- modify the config of the standby unit to remove references to failover. (might be best to erase the existing config and start a new config)
- configure the testing ASA for the test environment.
- conduct the testing.
- when testing is completed remove the testing config from the ASA.
- either restore the failover config that was backed up, or do enough basic config to allow the ASA to rejoin the ASA failover environment.
04-30-2020 08:49 AM
You are welcome. I am glad that my explanation was helpful. Thank you for marking this question as solved. This will help other participants in the community to identify discussions which have helpful information. Your marking and points awarded are correct. No need to change anything.
04-30-2020 06:06 AM
- The question is kind of irrelevant because if you want to use one for testing another Internet connection, then it will need another configuration anyway (so either you the pair in failover-mode., or you configure 2 boxes with 2 different purposes).
M.
04-30-2020 07:43 AM
Perhaps there are aspects of the original post that we do not understand, but it seems a fairly straightforward question. If there is a pair of ASA configured for active/standby failover and you want to use one of the ASA for testing I would suggest these steps:
- identify which ASA is currently the standby unit.
- make a copy of the config of the standby unit.
- disconnect that ASA that is the standby. The unit that is active will continue to be active, will maintain the same configuration, but would not be able to failover.
- modify the config of the standby unit to remove references to failover. (might be best to erase the existing config and start a new config)
- configure the testing ASA for the test environment.
- conduct the testing.
- when testing is completed remove the testing config from the ASA.
- either restore the failover config that was backed up, or do enough basic config to allow the ASA to rejoin the ASA failover environment.
04-30-2020 08:41 AM
thanks!. I'm not sure if I awarded points correctly. please let me know if i nee to change something
04-30-2020 08:49 AM
You are welcome. I am glad that my explanation was helpful. Thank you for marking this question as solved. This will help other participants in the community to identify discussions which have helpful information. Your marking and points awarded are correct. No need to change anything.
04-30-2020 08:39 AM
temporary test
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide