cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2435
Views
5
Helpful
1
Replies

Active/Standby ASA Failover Config Changes

Cody Ridge
Level 1
Level 1

Hello,

I have 2 ASA 5540s ver 8.3 in Active/Standby state.

I am considering a future hypothetical situation where I might need to rename interfaces or reallocate redundant interface groups.  Doing so obviously has a major impact on the current primary configuration.  My goal would be to minimize or eliminate network downtime during the interface changes.

I am wondering if it is possible to force the secondary ASA from the standby to active state.

Then temporarily disable failover on the primary unit.

Make the interface changes on the primary unit

Then reactivate failover on the primary unit

Force the primary unit back to active and secondary unit to standby

My new interface configuration would then sync from the primary to the secondary.

I believe this would work but must ensure that the secondary ASA can function as the active unit while the failover is disabled on the primary unit.  Is there a set length of time the secondary unit can remain active without a failover peer?

Does anyone see issues with operating the secondary unit in this manner while making changes to the primary unit?

Thank you

1 Accepted Solution

Accepted Solutions

varrao
Level 10
Level 10

Hi Cody,

That is the right way to do, the trAffic would pass normally through the secondary firewall so don't worry about it, thats the whole purpose of failover on ASA. The secondary would keep passing the traffic normally until it is active, there is no time limit to it. As far as your question regarding minimizing the downtime is concerned, I suggest you have a look at the virtual mac-address configuration and stateful configuration in failover. Here is the doc for it:

Stateful failover ----->http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml

Virtual mac-address------->http://www.cisco.com/en/US/partner/docs/security/asa/asa83/command/reference/m.html#wp2111374

Hope this helps.

Thanks,

Varun

Thanks,
Varun Rao

View solution in original post

1 Reply 1

varrao
Level 10
Level 10

Hi Cody,

That is the right way to do, the trAffic would pass normally through the secondary firewall so don't worry about it, thats the whole purpose of failover on ASA. The secondary would keep passing the traffic normally until it is active, there is no time limit to it. As far as your question regarding minimizing the downtime is concerned, I suggest you have a look at the virtual mac-address configuration and stateful configuration in failover. Here is the doc for it:

Stateful failover ----->http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml

Virtual mac-address------->http://www.cisco.com/en/US/partner/docs/security/asa/asa83/command/reference/m.html#wp2111374

Hope this helps.

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking products for a $25 gift card