07-04-2018 08:48 AM - edited 02-21-2020 07:56 AM
Does anyone know where I could find the instructions for replacing a failed unit in a ASA High Availability pair?
07-04-2018 02:03 PM
if it is Active /Active, it is easy to fail-over all the context to one ASA and replace fielded until
Active / Sandy it is easy too. compare to active active.
follow below thread will help you to easy steps :
https://supportforums.cisco.com/t5/firewalling/asa-failover-pair-hw-replacement/td-p/1445549
BB
07-05-2018 04:55 AM
Thanks but I also came across that thread. As the author says, they too cannot find a standard procedure.
07-04-2018 04:02 PM
Have you raised a TAC casxe with cisco yet, to RMA the failed unit? do this first
also, have you got a back up of the failing/failed unit?
07-05-2018 04:58 AM
Thanks for the reply but I was after the config instructions.
07-05-2018 05:32 PM - edited 07-05-2018 05:33 PM
Hello,
Here is roughly how I accomplish this:
! Presume the failover/crossover link is eth 0/3 failover lan unit secondary failover lan interface FAIL eth 0/3 failover key <Your_failover_Key_same_as_primary> failover replication http failover link FAIL eth 0/3 ! Presume this unit's failover link IP address is 192.168.255.254 and the other unit is 192.168.255.253 failover interface ip FAIL 192.168.255.253 255.255.255.0 standby 192.168.255.254 ! we have not yet enabled failover!
failover
If this was helpful, please mark it as such and mark the question solved. Thanks!
-A
02-19-2020 11:13 AM
how about if failed unit is primary?
02-19-2020 08:04 PM - edited 02-19-2020 08:04 PM
Same procedure except replace the word "secondary" with "primary". Those designations are more or less arbitrary since ASA HA doesn't have any concept of preemption. Either way the new replacement unit will detect an active mate and sync from it.
07-29-2020 12:04 AM
Dear Martin,
So the replication of the configuration will happen from secondary unit to primary as well? Taken under consideration that when the secondary unit is active all changes are replicated to primary unit , i presume the same for the failure scenario.
Thank you for the useful information!
07-29-2020 12:42 AM
Replication occurs from the unit currently in the Active role to the in Standby role. That's independent of whatever one is designated primary or secondary.
09-23-2020 01:21 AM
Is it recommended to disable failover on the active unit while waiting for the replacement unit or does it matter if failover still is enabled on the active unit?
Thanks
/Chess
09-23-2020 01:35 AM
It does not matter. I had this issue 2 times and never had to disable failover. When the replacement unit arrives configure the failover Link and connect only that to the network. When the replication is done you can connect the other interfaces and check the failover status using show failover command.
No need to failover to the replacement unit but i always do to check that it runs as it should. If you have a Firepower module it will need separate configuration.
KR
01-23-2021 08:54 AM
hi Arron Hackney.
Could you update the replacement steps for ASA 5516 HA active/Standby pair with firepower? Thanks
01-24-2021 06:17 AM
@qi guo The ASA procedure is the same.
Note the Firepower service modules have no HA relationship between one another. If you have a Firepower service module then you need to reimage to match the version you had before, do the bootstrap configuration and configure any policy you had on it. If you are using FMC then it is as easy as re-registering and deploying the policies stored on FMC. If you were using ASDM management for the Firepower service module then you need to configure everything from the start manually.
01-24-2021 08:08 AM
do you have any configuration example to share? i am using asdm, no FMC.
the question i still have are:
1.how to register the license of the new buy asa5516-x with firepower module? our environment is offline
2. as the firepower module of existing ASA55160-x never updated ios for a year, the new buy must have a different version. how to upgrade the existing one?
3.i have backed up the configuration of the existing firepower module. can i just deploy to the new buy to complete the firepower module configuration?
4. we bought the smartnet license for the new buy, how can i just register it into my smartnet account? do i just need the sale contract number and then contact Cisco?
Thx
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide