Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

ASA failover commands

Unanswered Question
Aug 16th, 2012
User Badges:

Hi there,

we have a pair of ASAs, one of which I need to move. For that I would like to turn off failover to be on the safe side.

Turning it off is described everywhere, but not how to turn it back on correctly (so that configs will sync again etc.).

So, how would I proceed for the entire process?

- First, I check if the one I'd like to remain in production is active. (If not I make it active using "failover active")

- Second, I say 'no failover' and this will have been the last command that will be issued automatically to both cluster members, and no automatic failover will occur.

- Then, I do whatever I have to do with the standby cluster member.

- When I'm finished, I do what exactly? Just say "failover" again to enable it? On both devices? (since both devices are not in sync anymore)



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jouni Forss Thu, 08/16/2012 - 03:04
User Badges:
  • Super Bronze, 10000 points or more


I haven't really had to move any firewall equipment in the failover pair but I have had to disconnect a secondary firewall because of a failover related problem (Configuration Sync didnt go through and the Secondary Firewall caused the whole pair to loose connectivity....for some reason).

Basically what I did in the situation was the following

- Disconnected the Secondary firewall from the network

- Erased the configurations from the Secondary firewall and reloaded it

- Configured the Secondary firewall with Failover configurations only

- Connected the Secondary firewall back to the network (everything but the actual Failover interface)

- Connected the Secondary firewall to Primary firewall with the failover cable (Actual firewalls located in 2 different datacenters)

- Watched as the Secondary firewall found the Primary firewall and started receiving the configuration from the Primary unit

The failover configuration on the Secondary device is the following (Primary devices configuration only difference is naturally that its defined as primary unit)


failover lan unit secondary

failover lan interface failover GigabitEthernet0/1

failover key

failover link failover GigabitEthernet0/1

failover interface ip failover x.x.x.x standby y.y.y.y

- Jouni

jer0nim0x Thu, 08/16/2012 - 04:48
User Badges:

That is exactly the thing I'd like to do (move one ASA to other datacenter)

Disconnecting the sync is not the hard part. The ASAs won't bother (active remains active, standby remains standby)

However, when the secondary's sync link goes back up (and suppose the sync transit network is not correctly configured) it won't see the primary, it will go active and we'll have a split brain scenario which I'd like to avoid...



This Discussion