05-18-2019 12:16 PM
Hi,
I have planning to implement secondary asa 5585 in HA so what I have configure in secondary device ???
05-18-2019 03:30 PM
here is good document to start with :
https://www.thegeekstuff.com/2011/09/cisco-asa-high-availability/
05-18-2019 07:31 PM
Hi ,
I have read the article but in my senario my primary is failed and secondary become active so I have to replaced new one in current live setup without affecting the secondary-active configuration.so what is the best way to complete this task.
05-18-2019 08:47 PM - edited 05-18-2019 08:48 PM
This has been answered several times over the years. ASA HA configuration has not changed significantly since, so the earlier threads remain valid:
https://community.cisco.com/t5/firewalls/replacing-primary-asa-in-h-a-pair/td-p/3369761 (2018)
Bottom line - you need only have the matching hardware and boot image (and any other files such as AnyConnect images) on the replacement unit. Give it a minimal failover config to match that on the failed unit and allow it to sync with the Secondary-Active. Then connect all the cabling and power it on. It should come up as Primary-Standby and synchronize running-config from the Secondary-Active unit. You may then (optionally) make it active with the command "failover active".
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide