cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

269
Views
0
Helpful
2
Replies
jpeterson6
Beginner

Replacing Failover cables in a production HA Setup

Hello,

When you need to bring down the Failover lan and state interfaces (ie, to replace cabling), what would be the best steps in order to prevent downtime, in a production environment?

If I unplug the failover cabling, how can I prevent both firewalls from going Active, assuming the other ASA is down? Will monitoring the 'inside' interface on both ASAs prevent this, so long as they can still reach each other?

Thanks.

1 ACCEPTED SOLUTION

Accepted Solutions
Marius Gunnerud
VIP Advisor

If there is no connection via the failover and state links the ASA will send test packets out its monitored interfaces to make sure there really is no connection to the standby ASA.  If the ASA gets a reply from the standby on the monitored interface failover will not occur.

So you should be ok when swapping the cables.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

2 REPLIES 2
Marius Gunnerud
VIP Advisor

If there is no connection via the failover and state links the ASA will send test packets out its monitored interfaces to make sure there really is no connection to the standby ASA.  If the ASA gets a reply from the standby on the monitored interface failover will not occur.

So you should be ok when swapping the cables.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

Okay, as I suspected. Thank you for the confirmation!

Create
Recognize Your Peers
Polls
Which of these topics should we host an event in the Community?

Top Choice: ISE- Guest and Posture Troubleshooting (67%)

Content for Community-Ad