11-21-2017 06:47 AM - edited 02-21-2020 06:48 AM
Hi,
We are having ASA 5555X single appliance with FTD running 6.2, Now we have to introduce HA standby appliance into the network.
What is the step by step approach to achieve this. Is there any downtime required for this?
Please help.
Thanks.
11-21-2017 07:18 AM
It can be done without downtime.
Steps would be:
1. install and configure the FTD on the new ASA
2. configure and activate the failover on the working ASA (should be configured as primary)
3. failover configuration on the new ASA (should be configured as secondary), but no activation
4. cable up the secondary ASA and activate the failover
5. Activate failover on the secondary, at this point it should get the configuration from the primary ASA and if everything is ok it will report as standby ready
Make sure you have the same version on the secondary ASA as the new one.
If your primary ASA is in multi context mode configure the secondary ASA in multi context as well.
The FTD on the secondary ASA will be used only when the secondary ASA will become active.
11-21-2017 07:35 AM
Bogdan - HA for FTD on ASA is not the same as regular ASA HA. HA for FTD can only be setup from Firepower Management Center.
Instructions for doing so can be found here:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide