Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

SSM-10 upgrade in Failover ASA (Active/Standby)

Hi,

 

I have an active/standby ASA with both fitted SSM-10. We are planning to do a software upgrade for the SSM-10. My concern here is the proper steps.

Should we start upgrade with the secondary unit first before we perform the upgrade for the Primary? Please advice.

 

Regards,

2 REPLIES

Yes, when the standby unit

Yes, when the standby unit has finished reloading, and is in the Standby Ready state, force the active unit to fail over to the standby. Reload the primary with the new image.

Gold

It all depends on your Fail

It all depends on your Fail Open setting and your security posture.

If your primary ASA is set to Fail Closed, then taking the AIP-SSM off line for an upgrade will cause traffic to fail over to the standby ASA. If you are set for Fail Open then traffic will continue to pass thru your primary ASA without IPS inspection untill the AIP-SSM comes back.

Your security posture will dictate how important IPS inspection/dropping is to your organization. Is mainting IPS inspection more important than failing over to the standby rail?

- Bob

 

40
Views
0
Helpful
2
Replies