Cisco ASA with FirePower - HA/failover to standby FMC
I have an ASA with FirePower and also have 2 x FMC in a HA configuration (over a layer 3). My question is, how does the ASA FirePower senor know how to failover to the secondary FMC in the event the primary FMC dies? Since the initial configuration on the ASA FirePower sensor only one FMC management IP is added/allowed.
Normally, when configuring HA FMC, your sensor should get a config with the 2nd FMC that will be used when primary fails. If it's not working, then you might need to go back to your sensor, remove the registration and re-do it. There was a link I already shared I believe in this forum. Here is the link with a quick and clear explanation: https://dependencyhell.net/2017/07/10/FMC-HA.html
Thanks Francesco PS: Please don't forget to rate and select as validated answer if this answered your question
Thank you for your reply. So to clarify; FMC's are in HA already. Once the ASA FirePower sensor is added with the primary FMC's IP, it should also receive config for the secondary FMC? If so, is there anyway to verify that from the console or is failing the primary FMC the only way to verify?
Multiple Cisco Security Technologies in a single book : ASA Firepower, WSA, Umbrella, ISE and VPN with 100 percent 100 practical scenarios with 70 Labs to cover important topics of the Cisco SCOR Exam. The best part is ISE with interesting scenarios wi...
Cisco Umbrella is a big DNS service that provides not only the DNS resolution but also if the hosted website is trust or malicious, the idea behind the Layer DNS Security is that the modern attacks uses the DNS in the first step either to redirect the use...
I shared with you this detailed document I created with 27 pages about Cisco ISE Integration With F5 BIG-IP Locar Traffic Manager LTM Load Balancer for Guest Acces.
The method used for Guest Access is the Self-Registration.
Healt Monitor using HTTP...
I created an IPSEC Site to site Tunnel between two ASA Firewalls in EVE-NG topology and i want to plot the IPSEC Site to Site VPN graph on PRTG ? The SNMP Walk command is not getting any output . As the firewall is making SNMP inbound connections with the...
The purpose of this document is to demonstrate how ISE can integrate with an eduroam external server which is a WI-Fi roaming service that provides international access to devices in education, research, and higher education. Students, teachers, and resea...