cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
311
Views
0
Helpful
4
Replies

Restore an FTD -- from backup or from HA sync?

brettp
Level 1
Level 1

I am little confused. What is the preferred or best method of restoring a re-imaged FTD (1000 series) that was part of an HA pair? Is it better to run a restore from backup... Or is better to simply configure the device with a barebones config and set up the HA pair again (allowing the primary to push the config.) What is the difference or the pros/cons? Any insight is appreciated. Thanks!

1 Accepted Solution

Accepted Solutions

@brettp

There is a guide that covers both methods:-

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221097-replace-faulty-unit-in-secure-firewall-t.html

IMO, I would configure the barebones config of the management IP address and re-register with the FMC, rather than restore from backup.

 

View solution in original post

4 Replies 4

@brettp

There is a guide that covers both methods:-

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221097-replace-faulty-unit-in-secure-firewall-t.html

IMO, I would configure the barebones config of the management IP address and re-register with the FMC, rather than restore from backup.

 

brettp
Level 1
Level 1

@Rob Ingram Thank you for your input! Do you know if there are any pros or cons to one method or the other? 

@brettp well, using the backup/restore method might take slightly longer doing the restore and a subsequent reboot, and the configuration would still be synchronised from the active unit. The other method does not rely on a backup configuration (which would maybe out of date anyway) and has less steps, taking slightly less time to complete.

I always prefer to let HA sync the configuration when the device is in an HA pair.  This is due because the active device will always sync its configuration to the standby overwriting any existing configuration already there. 

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card