This document lists the basic steps that we need to follow when we need to introduce the Failed (Primary) unit back in the High Availibilty configuration.
Verify these things on both the Units:-
- The two units in a failover configuration must be the same model, have the same number and types of interfaces, the same SSMs installed (if any), and the same RAM installed.
- The two units in a failover configuration must be in the same operating modes (routed or transparent, single or multiple contexts). They must have the same major (first number) and minor (second number) software version. However, you can use different versions of the software during an upgrade process; for example, you can upgrade one unit from Version 7.0(1) to Version 7.0(2) and have failover remain active. We recommend upgrading both units to the same version to ensure long-term compatibility.
- Both the units need to have the same licenses. For ASA 8.3.1 and above, the two units in a failover configuration do not need to have identical licenses; the licenses combine to make a failover cluster license. Still make sure that both units have failover license enabled.
- Make sure the Failover interface cables are connected to the switch in the same VLAN with PORTFAST ports configuration or directly before continuing with these steps.
We have two options while introducing the Failed (Primary) unit back in the HA Pair:-
- Introducing the Failed (Primary) unit as Primary (Standby) device.
No configuration changes are required. You just need to copy the exact failover configuration from the existing Secondary (Active) unit with the exception of this command:-
Failover lan unit primary
NOTE: - The configuration replication will happen from the Active to the Standby Unit. When the Failed (Primary) unit is introduced into the network, if the cable are connected properly between the Fail-over interfaces, it will detect the Secondary (Active) as the active unit and will automatically become the Primary (Standby).
2. Making the Failed (Primary) unit as Secondary (Standby) device.
- Disable the failover on the Secondary (Active) unit.
- Change this command on this unit to:-
Failover lan unit Primary
- Configure the Failed (Primary) unit with the same configuration with exception of this command:-
Failover lan unit secondary
- Enable the failover and the configuration will replicate successfully between these two devices.
Note: - If you have a switch connecting the Failover interface, please clear the arp for the failover interfaces as the MAC address would be different for the replaced unit.
Refer:-
ASA device configuration Guide
http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/configuration/guide/config/ha_overview.html
ASA device command reference
http://www.cisco.com/c/en/us/td/docs/security/asa/command-reference/cmdref.html
License requirement (before or on ASA 8.2)
http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/license/license82.html