02-01-2021 10:05 AM
Dear All,
I have a standalone FMC managing 2 FTDs in HA, Recently I observed that Primary unit is showing disabled and secondary take on as active.
During trouble shooting,
To Resolve the Issue, below are my POA
My Queries and suggestion from forum
1.How do I add The FTD back to HA [ Note it is Primary unit to HA]
2.When I add in HA, how do I ensure the secondary unit [ which is now active ] with not take that configuration from Primary unit and whole configuration will not get erased,
Will appreciate if someone can help me to mitigate the risk ,I would be thankful if anyone shares me solution based on experience.
Thanks
Bibek
02-01-2021 01:39 PM
Here is our experience with something similar.
I broke our HA a few weeks ago to fix interface configurations. At that time both units FW1 and FW2 kept their configurations. We had to de-register the secondary from FMC since we wanted to keep the configuration that was already on the primary. We removed the HA link between the two and brought the primary back on line. Once that was stable we registered the secondary with FMC. We then reconnected the HA link between the two and started the HA configuration from scratch. Of course this wiped the secondary configuration and copied over the primary configuration. We don't have the Firewall chassis manager so I'm not sure how that plays into the mix.
It sounds like you don't want the configuration on the secondary to get wiped.
I'm not sure how that's going to work because from my reading it will always get wiped when introduced into HA.
I would suggest reading up on the "sync" function once you get both units re-registered with the FMC and the management interface issue fixed.
We too have had some odd issues with FMC/FTD HA working as expected/advertised.
02-03-2021 08:22 AM
HI,
Thanks for sharing your experience, Actually the configuration swiped out from my Primary unit [ I don't know the reason] and everything is working on Secondary Unit
The failover-link , State link-link and Data ports are showing Status " admin down" on primary unit where as
failover-link port and Statelink port are showing Status " admin up in Secondary unit" So I have believe the configuration is wiped out
My risk factor is that Secondary should not copy the configuration from Primary unit, So I am planning to perform the below POA
Pls suggest if I am missing anything or there would be change in POA
BR
Bibek
02-03-2021 12:40 PM
That sounds like a plan.
I probably would have gone with your steps, remove cabling, remove previous Primary from FMC and re-add then recreating the HA by making the secondary the primary. Provided the now secondary has the proper configs.
In either case won't the down primary have all the proper configs by default from the up secondary once you re-introduce HA?
I'm asking because your mention doing a sync.
Sorry if I'm missing something in your steps that provides this answer.
Please post your results as we have had some issues with how HA works when breaking it or restarting one the FTD's.
We had an issue where selective sites were not accessible.
The logs point to a PAT pool exhaustion episode.
ej
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide