cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1599
Views
0
Helpful
4
Replies

ASA failover mode change from active/active to active/standby

anva12345
Level 1
Level 1

Hi All

   we have two fireawalls configured in active/active mode with two context.All the interface of two contexts are shared.How can i change the mode of failover from active/active to active/standby with minimum disruption

Thanks in advance

4 Replies 4

Andrew Phirsov
Level 7
Level 7

I think you just have to delete join-failover-group command under your individual contexts. When it's done, all contexts will belong to the same failover group and only one appliance will be active.

Plus delete everything, related to your second failover group from the admin context, i.e. do no failover-group 2.

Thank you Andrew for the response.

In our case,we have two context named A1 and A2.A1 is active on ASA-1 and A2 is active on ASA-2.What we require is to transfer all traffic for A2 to A1(this can be done by changing the routing on upper and down layer) and delete A2.After that change the mode from multiple to single and make the two firewalls in active/standby failover.Is this possible without any disruption.When we change mode from multiple to single,ip address configured for context interfaces will be migrated to orginal physical interface?

When you change from multiple to single, your config will be lost, nothing will be migrated.

Here is my idea, I would make both contexts active in one of the ASA, this way, the traffic will flow to one ASA only and you can play around with the other ASA (change it to single, delete the context, port over the config from multi to single, etc.). Once the second ASA is ready to deploy, you transfer the traffic (A2 to A1) on first ASA, delete the A2 context, then transfer the whole traffic to the second ASA, after that you can start convert the first ASA to single, make it as secondary or primary, etc. (make sure that one ASA is able to handle traffic from both contexts).

Looking above scenario, you should have minimum disruption. Please keep in mind that above is only for Active/Standby single mode ASAs scenario, not for Active/Standby on multiple mode ASAs scenario.

HTH

Review Cisco Networking for a $25 gift card