cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1775
Views
5
Helpful
4
Replies

cisco ASA failover configuration

I currently run a ASA 5525-X in active/standby routed mode.

 

Is there a way to make the primary unit always be the active? Other firewall manufactures allow you to give the active and standby units a preempt priority level unique to each unit. When configuring my Palo Alto active/standby HA firewall I gave the primary unit a preempt priority of 5 and the standby unit a preempt priory of 10 (lower priority = preferred unit). This assures me that when the firewall is running normal with no issues with either unit, the Primary unit will always be the active unit. If I were to reload the primary unit - the secondary unit would be come active - once the primary unit has reloaded it would automatically become the active again due to having the lower preempt priority. When my environment is running normal I like to have the Primary unit be active  - I am able to do this with my juniper and palo Alto firewall using the preempt priority mechanism - not so with my cisco ASA. 

 

 

 

1 Accepted Solution

Accepted Solutions

Hi,

In ASA this is called preempt. Its available in multicontext mode. Its not
present in single context. Changing to multicontext is a major activity so
if you want to go that way, plan for it with outage window.

***** please remember to rate useful posts

View solution in original post

4 Replies 4

vsurresh
Level 1
Level 1

Hello.

As far as I know, A/S failover does not support preemption.

Preempt option is available on A/A failover.

 

 

Hi,

In ASA this is called preempt. Its available in multicontext mode. Its not
present in single context. Changing to multicontext is a major activity so
if you want to go that way, plan for it with outage window.

***** please remember to rate useful posts

AViftrup
Level 1
Level 1

As mentioned above, it's not possible in single context. 

 

It's basically irrelevant to the running system whatever system is the active one, it's only a matter of display. I get it might be annoying, but it doesn't have any technical differences. 

Thanks everyone

Review Cisco Networking products for a $25 gift card