I have 2 * ASA5515-IPS-K9 that were purchased last year and were configured as 2 separate firewalls and IPS modules. Although there were some initial teething problems with the IPS's being able to communicate the Internet for signature updates, this was resolved with assistance from TAC's. The ASA's have recently been reconfigured to work in a Active/Standby failover configuration, with everything working and functioning correctly. But it now seems like there are some serious issues with the IPS modules. The IPS in the 'Active' unit is 'not connected' and i am unable to reconnect to it via IME (7.2.1). The second module is connected but states that the signature definitions are out-of-date although the automatic signature download say's that it's work correctly! The units are installed in a remote data centre, but i have got full remote acces to them. My questions are: What happens to the IPS module in the 'Standby' unit, does it stay live or should it shutdown into standby? What is the correct configuration for the IPS modules in this scenario? How can i restore correect functionallity to these units?
... View more