cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
658
Views
3
Helpful
6
Replies

ASA5525 HA pair: ASDM only accessible to secondary (not primary)?

ASA5525 HA pair: ASDM only accessible to secondary (not primary)...

Hello.

With ASDM software I am able to access the ASA pair only through the secondary device (ip address). 

When I try with the primary IP address, I receive error "unable to launch device manager from !!ASA address!! 172.16.1.15" (attached below)

When I try to just use the secondary access, when I am about to save config, I receive warning that devices will no longer be in synch.

I ran pcap-- my workstation and the ASA are exchanging application packets on port 443. (attached below)

May you please assist on remediating this symptom?

Thank you.

1 Accepted Solution

Accepted Solutions

@jmaxwellUSAF is the ASDM image uploaded to the flash on primary ASA?

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/110282-asdm-tshoot.html

Confirm whether the image is in flash - show asdm image

 

View solution in original post

6 Replies 6

@jmaxwellUSAF is the ASDM image uploaded to the flash on primary ASA?

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/110282-asdm-tshoot.html

Confirm whether the image is in flash - show asdm image

 

Hi Rob.

The below symptom expressing devices not in sync, disturbs me. 

How can I ensure this HA pair is in synch?

Thank you.

"stby(config)# asdm image disk0:/asdm-7191-90.bin
Device Manager image set, but unable to find disk0:/asdm-7191-90.bin
**** WARNING ****
Configuration Replication is NOT performed from Standby unit to Active unit.
Configurations are no longer synchronized."

@jmaxwellUSAF the ASDM image file must be manually copied to both peer devices, once the same image is in the same location on both ASA apply - "asdm image disk0:/asdm-7191-90.bin" on the primary firewall. You entered the command on the standby, that won't be synced to the primary.

Yes, I fixed that.

Am I correct in understanding that this warning was just 1-time local to that command, and everything else will continue to be synched?

Thank you.

@jmaxwellUSAF you'd see that command if you made any changes on the standby appliance. You should ensure you make all changes on the primary ASA only.

If you wish to test synchronisation is still working ok, make an innocuous change from the primary ASA, save the configuration and observe the configuration on the standby ASA.

Thank you!

Review Cisco Networking products for a $25 gift card