Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Swap primary secondary role in Cisco ASA 7.2

I have2  pairs of cisco 5520 and cisco 5550 running 7.2 software working in active/standby mode in single context mode.

I want to  change the primary and secondary roles of firewalls without any downtime. What is the best way to do this?

failover exec mate failover lan unity primary command does this but its not available with asa software image 7.2

Super Bronze

Swap primary secondary role in Cisco ASA 7.2


I am not sure if this is really needed.

The Active device in the Active/Standby stays as Active as long as its operational and doesnt have any problems.

So even if you have a Failover device configured as "primary" and it happens to fail and come back up again, it shouldnt to my knowledge return back as Active UNLESS its manually set so or if the currently Active device fails.

To my understanding it mostly matter in the event that both devices boot pretty much at the same time. Then the "primary" and "secondary" settings will determine which one of the units is selected as Active.

There should be no preempt type of action in an Active/Standby setup. Active/Active on the other hand permits the use of "preempt" setting which will return the "primary" device as the Active when its operational again from a possible fault.

I have not had to change this setting on any existing Failover environments we have so I am not sure if it will have any effect on the Failover.

- Jouni

New Member

Swap primary secondary role in Cisco ASA 7.2


Evenif it doesnt have any issues on operations and on active/standby status, we need it as a part of our standardisatin policy. As we want all firewalls in our primary data center to be active and primary.

Currently firewall in my primary data center is active and secondary which should be primary as per our policy.

I would like to know if changing primary/secondary will impact failover operation and how to add it with least searvice disruption?

Super Bronze

Swap primary secondary role in Cisco ASA 7.2


As I have not had to do this personally I can't say anything for sure.

I can't also remember reading anything from Cisco related to this so I can only guess that this wont affect the state of the Failover as it doesnt really play a part in the roles of the Active/Standby devices unless they are both booted up.

But as it is with any things I personally dont know I rather schedule a maintanance break or use an already planned break to do these changes to be able to react to unexpected behaviour and cause the least amount of downtime to any services.

So I can't really give an 100% sure answer on this and I dont currently have devices at hand that could be used to test this.

- Jouni

CreatePlease to create content