01-30-2014 12:56 PM - edited 03-11-2019 08:38 PM
Hello,
When you need to bring down the Failover lan and state interfaces (ie, to replace cabling), what would be the best steps in order to prevent downtime, in a production environment?
If I unplug the failover cabling, how can I prevent both firewalls from going Active, assuming the other ASA is down? Will monitoring the 'inside' interface on both ASAs prevent this, so long as they can still reach each other?
Thanks.
Solved! Go to Solution.
01-30-2014 01:05 PM
If there is no connection via the failover and state links the ASA will send test packets out its monitored interfaces to make sure there really is no connection to the standby ASA. If the ASA gets a reply from the standby on the monitored interface failover will not occur.
So you should be ok when swapping the cables.
--
Please remember to rate and select a correct answer
01-30-2014 01:05 PM
If there is no connection via the failover and state links the ASA will send test packets out its monitored interfaces to make sure there really is no connection to the standby ASA. If the ASA gets a reply from the standby on the monitored interface failover will not occur.
So you should be ok when swapping the cables.
--
Please remember to rate and select a correct answer
01-30-2014 01:10 PM
Okay, as I suspected. Thank you for the confirmation!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: