12-07-2012 10:29 AM - edited 03-11-2019 05:34 PM
Preparing to upgrade the IOS on a faillover pair of ASA 5580's and was wandering what is gonna happen after I've upgraded the IOS on the standby unit and rebooted. How is the active unit going to react when it sees an IOS mismatch prior to me making the standby the primary and upgrading it's IOS ?
Thanks, for any help.
12-07-2012 10:46 AM
Hello Andrew,
There shouldn't be any problems, please follow this guide to perform upgrade on failover pair:
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mswlicfg.html#wp1057338
Please rate helpful posts
Best Regards,
Eugene
12-07-2012 10:47 AM
Andrew,
During the upgrade in failover there is going to be a mismtach for a few minutes between each other. It should not be a problem if it is only a few minutes.
The correct procedure is below:
-Copy the binary image (asannn.bin) to the root directory of the TFTP server.
-Issue the copy tftp flash command in order to copy the new ASA image to the Primary ASA.
-Issue the copy tftp flash command in order to copy the new ASA image to the Secondary ASA.
2- On the Active (Primary) Firewall:
-No boot system flash:
-boot system flash:
-write memory
-failover reload standby
-no failover active
-reload
3- On the Standby (Secondary) Firewall:
-no failover active
Regards,
Juan Lombana
Please rate helpful posts.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide