11-21-2012 07:01 AM - edited 03-11-2019 05:26 PM
Hi,
We have FWM-1 working in active/standby inter-chassis failover.
The primary unit had some problems and the secondary took over the functions.
I intend to change the failover settings and put the secondary unit to be the primary and vice-versa.
Can I 'promote' the secondary unit to primary without any risk to stop its services?
Anyone know some issue related?
Regards
11-21-2012 08:16 AM
Hi,
I can't say for sure without checking documentation but I will tell how the ASAs work. (To my understanding this should apply to FWSM also)
The ASA doesnt seem to have anykind of mechanism at the monent (In Active/Standby setup) where it would change the active firewall unless there is a real network problem causing this change or admin changes the active device manually. So to my knowledge the settings "primary" and "secondary" arent important with Active/Standby setup
Active/Active setup with ASAs on the other hand lets you use a "preempt" feature (like with router HSRP configurations) that will let you define a time perioid after which a certain ASA will always take the Active role after it has recovered.
In other words, lets say you have Active/Active ASAs (meaning 1 Security Context/Virtual Firewall active on each ASA as both are Active)
- Customer1 context is active on ASA1
- ASA1 fails and ASA2 becomes active for Customer1 context
- "preempt" timers are configured under failover-group configurations
- ASA1 recovers from the fault (perhaps boot because of power failure at datacenter)
- After "preempt" timer has run its course the ASA1 will again become Active for Customer1 context
So unless you are using Active/Active failover the "failover lan unit primary/secondary" should not matter that much for you.
Here is a direct quote of FWSM command reference for the command in question:
failover lan unit
To configure the FWSM as either the primary or secondary unit in a failover configuration, use the failover lan unit command in global configuration mode. To restore the default setting, use the no form of this command.
failover lan unit {primary | secondary}
no failover lan unit {primary | secondary}
Usage Guidelines
For Active/Standby failover, the primary and secondary designation for the failover unit refers to which unit becomes active at boot time. The primary unit becomes the active unit at boot time when the following occurs:
•The primary and secondary unit both complete their boot sequence within the first failover poll check.
•The primary unit boots before the secondary unit.
If the secondary unit is already active when the primary unit boots, the primary unit does not take control; it becomes the standby unit. In this case, you need to issue the no failover active command on the secondary (active) unit to force the primary unit back to active status.
For Active/Active failover, each failover group is assigned a primary or secondary unit preference. This preference determines on which unit in the failover pair the contexts in the failover group become active at startup when both units start simultaneously (within the failover polling period).
This command must be part of the configuration when bootstrapping an FWSM for failover.
Hope this helps
- Jouni
11-22-2012 03:41 AM
Hi Jouni,
That is my doubt because I also know how ASA works.
As I know that there are differences between ASA and FWSM I need to take much care with any changes in the FWSM.
Thanks for help.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: