05-09-2023 06:03 AM
Hi All
I got ASA firewalls in HA pair (Active/standby) in old DC. I need to migrate this firewalls to new DC with no downtime. Am planning to do the below, please let me know if this works, Port1 in Active fw is connected to port1 in Standby firewall:
* Disconnect the HA cable (port1) in Secondary firewall and other data cables and shutdown the secondary firewall and move to new DC.
* There is a fibre cross connect between old and new DC connected via 3750 switch, in Old DC connect port1(HA port) from primary firewall to copper port in switch on VLAN720 (Access port) and also configure Fibre port (cross connect between old and new DC) as access port in VLAN720.
* In new DC 3750 switch, configure Fibre port (cross connect between old and new DC) as access port in VLAN720 & copper port on VLAN720 (Access port) and connect port1 (HA port) from secondary firewall to the switch copper port and power on the firewall.
* Once the firewall is online make sure it is secondary (sh failover) and then connect all data ports to the new DC switch (trunk all the data VLAN's between old and new DC).
* Then disconnect the primary firewall in old DC and connect the HA and other data ports in new DC and failback the firewalls in new DC.
05-12-2023 07:53 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide