cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1776
Views
10
Helpful
5
Replies

ASA 5516 Standby Active and Firepower(Virtual)

mape18
Level 1
Level 1

Hi

I have one Asa 5516 up and running with Firepower Services (the firepower is a virtual server). I´m going to install an other Asa so they are in failover Active Standby and  don´t really know how to manage Firepower. i hope somebody can help me, thanks in forward!

2 Accepted Solutions

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

Firepower module can be manage with ASDM with Limited, but if you like to manage fully then FMC is good option.

 

If you bringing other device of ASA making HA, you should have same like a like hardware for to build HA if you like both ASA and FP to be HA .

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

balaji.bandi
Hall of Fame
Hall of Fame

If the new ASA / FP going to be standby, you need to basic config add master so  primary will sync all to secondary in HA environment.

 

ASA  need to configure as per below document :

 

https://www.petenetlive.com/KB/Article/0000048

 

FP you need to configure management interface and register with FMC then do HA between FP Service module.

 

Note: always take the configuration and backup out of the box, Make sure no changes while making HA, or making FP HA

 

always do in a maintenance window, to avoid business continuity.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

Firepower module can be manage with ASDM with Limited, but if you like to manage fully then FMC is good option.

 

If you bringing other device of ASA making HA, you should have same like a like hardware for to build HA if you like both ASA and FP to be HA .

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for the answer. Well it is FMC we have. So what i have to do is to install firepower on the new Asa with connection to the FMC

balaji.bandi
Hall of Fame
Hall of Fame

If the new ASA / FP going to be standby, you need to basic config add master so  primary will sync all to secondary in HA environment.

 

ASA  need to configure as per below document :

 

https://www.petenetlive.com/KB/Article/0000048

 

FP you need to configure management interface and register with FMC then do HA between FP Service module.

 

Note: always take the configuration and backup out of the box, Make sure no changes while making HA, or making FP HA

 

always do in a maintenance window, to avoid business continuity.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yes, the new Asa will be Standby, thanks for the details in your reply!

The ASAs take care of all the HA bits.

The Firepower service modules will not be HA per se. They can be managed as a group from FMC (apply same policies) but they don't fail over (i.e., active-standby roles) on their own. Each Firepower service module runs independently and has no awareness of the other one.

Review Cisco Networking for a $25 gift card