cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
582
Views
0
Helpful
1
Replies

ASA HA query

Psmurali89
Spotlight
Spotlight

Hi All

I got ASA firewalls in HA pair (Active/standby) in old DC. I need to migrate this firewalls to new DC with no downtime. Am planning to do the below, please let me know if this works, Port1 in Active fw is connected to port1 in Standby firewall: 

* Disconnect the HA cable (port1) in Secondary firewall and other data cables and shutdown the secondary firewall and move to new DC. 

* There is a fibre cross connect between old and new DC connected via 3750 switch, in Old DC connect port1(HA port) from primary firewall to copper port in switch on VLAN720 (Access port) and also configure Fibre port (cross connect between old and new DC) as access port in VLAN720. 

* In new DC 3750 switch, configure Fibre port (cross connect between old and new DC) as access port in VLAN720 & copper port on VLAN720 (Access port) and connect port1 (HA port) from secondary firewall to the switch copper port and power on the firewall. 

* Once the firewall is online make sure it is secondary (sh failover) and then connect all data ports to the new DC switch (trunk all the data VLAN's between old and new DC). 

* Then disconnect the primary firewall in old DC and connect the HA and other data ports in new DC and failback the firewalls in new DC. 

1 Reply 1

Your plan to migrate the ASA firewalls in an HA pair to a new data center without downtime seems to be well thought out. Here's a summary of the steps you've outlined and some additional considerations:

1. Disconnect the HA cable (Port1) and other data cables in the secondary (standby) firewall, and shut it down. Move the standby firewall to the new data center.

2. In the old data center, connect Port1 (HA port) from the primary (active) firewall to an access port in the 3750 switch on VLAN720. Configure the fiber port (cross-connect between old and new data center) as an access port in VLAN720.

3. In the new data center, configure the fiber port (cross-connect between old and new data center) as an access port in VLAN720 on the 3750 switch. Connect Port1 (HA port) from the secondary firewall to an access port on the switch in VLAN720 and power it on.

4. Verify that the secondary firewall is online and in standby mode (using "sh failover"). Connect all data ports to the new data center switch, trunking all data VLANs between the old and new data center.

5. Disconnect the primary firewall in the old data center and connect the HA and other data ports in the new data center. Fail back the firewalls in the new data center.

This plan should work, assuming that:

- The cross-connect between the old and new data centers has sufficient bandwidth to handle the traffic during the migration.
- The 3750 switches in both data centers are properly configured for VLAN720 and trunking between the old and new data centers.
- The ASA firewalls have the correct licensing and configuration for HA functionality.

Please also ensure that you have a rollback plan in place, in case any issues arise during the migration. It's essential to have a backup of the configurations, and coordinate closely with your team during the entire process to minimize any potential risks.

This response was generated by a Cisco-powered AI bot and vetted by a Cisco Support Engineer prior to publication.
This is part of a monitored experiment to see if the bot can help answer questions alongside community members. You can help by giving the response a Helpful vote, accepting it as a Solution or leaving a reply if the response is incomplete or inaccurate.
Review Cisco Networking for a $25 gift card