05-16-2011 09:16 AM - edited 03-11-2019 01:34 PM
Hello,
I have 2 ASA 5540s ver 8.3 in Active/Standby state.
I am considering a future hypothetical situation where I might need to rename interfaces or reallocate redundant interface groups. Doing so obviously has a major impact on the current primary configuration. My goal would be to minimize or eliminate network downtime during the interface changes.
I am wondering if it is possible to force the secondary ASA from the standby to active state.
Then temporarily disable failover on the primary unit.
Make the interface changes on the primary unit
Then reactivate failover on the primary unit
Force the primary unit back to active and secondary unit to standby
My new interface configuration would then sync from the primary to the secondary.
I believe this would work but must ensure that the secondary ASA can function as the active unit while the failover is disabled on the primary unit. Is there a set length of time the secondary unit can remain active without a failover peer?
Does anyone see issues with operating the secondary unit in this manner while making changes to the primary unit?
Thank you
Solved! Go to Solution.
05-16-2011 09:39 AM
Hi Cody,
That is the right way to do, the trAffic would pass normally through the secondary firewall so don't worry about it, thats the whole purpose of failover on ASA. The secondary would keep passing the traffic normally until it is active, there is no time limit to it. As far as your question regarding minimizing the downtime is concerned, I suggest you have a look at the virtual mac-address configuration and stateful configuration in failover. Here is the doc for it:
Stateful failover ----->http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml
Virtual mac-address------->http://www.cisco.com/en/US/partner/docs/security/asa/asa83/command/reference/m.html#wp2111374
Hope this helps.
Thanks,
Varun
05-16-2011 09:39 AM
Hi Cody,
That is the right way to do, the trAffic would pass normally through the secondary firewall so don't worry about it, thats the whole purpose of failover on ASA. The secondary would keep passing the traffic normally until it is active, there is no time limit to it. As far as your question regarding minimizing the downtime is concerned, I suggest you have a look at the virtual mac-address configuration and stateful configuration in failover. Here is the doc for it:
Stateful failover ----->http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml
Virtual mac-address------->http://www.cisco.com/en/US/partner/docs/security/asa/asa83/command/reference/m.html#wp2111374
Hope this helps.
Thanks,
Varun
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide