cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1137
Views
20
Helpful
4
Replies

HA Firepower 2130

Pedro Coelho
Level 1
Level 1

I have set up HA on my firewalls and both the primary and secondary are in active and I can't change this state

1 Accepted Solution

Accepted Solutions

For HA to work both unit must have same model and same software plus same physical module on each chassis. The best practice is to use the same ports on same units instead of mixing the ports with each individual etc.

 

for sfp port is your sfp is compatiable and is working? have you tired these sfps on different set of hardware to confirm they are working. also could you see the light is coming out from the fiber cable etc.

 

as mentioned earlier check on FTD "show failover" or "show failover | i host", "show failover history" to see if each unit see each other. how these FTD are managed on FMC or standalone in HA pair.

 

 

 

 

please do not forget to rate.

View solution in original post

4 Replies 4

@Pedro Coelho 

Have you setup the interfaces in the correct VLANs? check the switch configuration

Can the firewalls communicate with each other?

Have you setup the HA and state links? and connected together correctly?

 

Run "show failover history" and "show failover" and provide the output

 

Follow this guide

https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html

 

 

 

 

 

I am trying to make a direct connection between the firewalls, with the spf ports

And i use different ports for different links

For HA to work both unit must have same model and same software plus same physical module on each chassis. The best practice is to use the same ports on same units instead of mixing the ports with each individual etc.

 

for sfp port is your sfp is compatiable and is working? have you tired these sfps on different set of hardware to confirm they are working. also could you see the light is coming out from the fiber cable etc.

 

as mentioned earlier check on FTD "show failover" or "show failover | i host", "show failover history" to see if each unit see each other. how these FTD are managed on FMC or standalone in HA pair.

 

 

 

 

please do not forget to rate.

only reboot the secondary,

Review Cisco Networking for a $25 gift card