cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2997
Views
5
Helpful
1
Replies

Synchronization of VPN-related config with failover-ASAs

Hi all,

on the ASA, there many many configurations that are not in the running-config any more, but in xml-files on the flash filesystem.

I'm looking for a documentation, which VPN-elements are replicated to the ASA standby-unit and which are not. I.E. the clientless bookmarks are replicated, but the anyconnect-profiles are not.

And are there any ways to keep both units in sync without having to manually copy everything to both units?

Regards, Karsten

1 Accepted Solution

Accepted Solutions

Nicolas Fournier
Cisco Employee
Cisco Employee

Hi Karsten,

Anyconnect images. CSD ones and Anyconnect profiles are not replicated between the two devices, the rest is.

To make it even simpler, all the data which is saved in a hidden file system are replicated while the ones you see when issuing a "show flash" are not.

For now, thew only way to have this working is to go manually to each unit and to install the files there but there is an enhancement request to have the automatic replication implemented: CSCsr31403  AnyConnect and CSD images and client profiles are not copied to standby.

Regards,

Nicolas

View solution in original post

1 Reply 1

Nicolas Fournier
Cisco Employee
Cisco Employee

Hi Karsten,

Anyconnect images. CSD ones and Anyconnect profiles are not replicated between the two devices, the rest is.

To make it even simpler, all the data which is saved in a hidden file system are replicated while the ones you see when issuing a "show flash" are not.

For now, thew only way to have this working is to go manually to each unit and to install the files there but there is an enhancement request to have the automatic replication implemented: CSCsr31403  AnyConnect and CSD images and client profiles are not copied to standby.

Regards,

Nicolas