Procedure to upgrade (Active-Standby) ASA

Hi all

I just want to check if our upgrade scheduled SAA causes no problems during the procedure.

Material: ASA5525-X

Existing IOS: 9.1.2

Update to: 9.4.2 (11)

Setup: Active standby

We intend to be upgraded the first start, after that, is the day before still will to resume after we force a failover him so that we can then pass the main firewall.

Thank you very much!

Yes, it's the process. I did it several times it it works perfectly when you follow the documented procedure.

http://www.Cisco.com/c/en/us/support/docs/security/ASA-5500-x-series-NEX...

Tags: Cisco Security

Similar Questions

  • Update software remotely active / standby ASA 5520

    Hello

    We have a pair of 5510 s and a pair of 5520 s, each active mode / standby.  I would like to upgrade the ASDM and ASA software on these, but can't find any documentation that advise on how this can be done without physical access to devices.  There I am on the site, but we will deploy these all throughout our network and I would like to be able to perform this type of maintenance without having to travel to each site.

    We use CSM and ASDM to manage these most of the time, but are certainly capable of configuration via the CLI.

    The question may be my understanding lack the foundations of the ASA, but I really don't understand how the software can be copied to the ASAs individual of the pair so that they can be reloaded and updated continuously.  My lack of understanding also makes a difficult word question, so please forgive me that.  With a remote SSH connection to the pair, I only copy the correct software to the ASA Active?  Or y at - it a way to get the software on each disk individually in the only SSH connection?  I'm not sure how to handle the ASA ensures no comfort in it... If I can get to remote software at each ASA (copy on different disks? i.e. disk0: and disk1:?), while I will also meet a problem to update startup for each statement individually, but to solve that I guess I could just remove the old software, but cela seems bad practice before confirming the new software is ok.

    If there is an easier way to deploy the new code via ASDM or CSM, I am certainly open to that.

    Any advice or resources that anyone could offer would be extremely useful and appreciated.

    Thank you

    Justin

    Justin,

    This is exactly why. If you are using version prior to version 8.4.1, routing table information is not replicated between the devices.

    Information that is not transmitted to the rescue unit when the rollover is enabled includes these:

    • The HTTP connection table (except if the HTTP replication is enabled)

    • The user authentication (uauth) table

    • The routing tables

    • Status information for the security service modules

    http://Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml

    If your gateway of default route is learned via EIRGP and you are trying to access from the internet, you won't be able to get to the secondary unit.

    Workaround solution, put the default gateway static with a metric higher while it appears on the running configuration and sent to the secondary unit.

    Of the questions let me know.

    Mike

  • Cisco ASA CX active / standby

    Hello friends

    One of my clients has a couple of ASA 5545 work quite well as active / standby failover. But the configuration that is not copied to the secondary unit is CX. Do you know how to get it? Please, do not hesitate to request further information, comment or document will be appreciated.

    Kind regards!

    The CX configurations are not part of the active reserve ASA replication.

    How to synchronize the configurations of CX is to use PRSM (first Security Manager - product under separate license, not the one provided with the CX) running on a virtual machine in device mode.

    Reference.

    Once you find out what pair CX with a PRSM "out of area", all configuration changes are deployed both to the pair.

  • ASA 5520 Active standby and ssl vpn loadbalancing

    I have a pair of Asa 5520 failover active rescue running. Can I use these two machines in a cluster of ssl vpn load balancing?

    N ° when a couple active / standby is part of a cluster of VPN, the rescue unit is still pending - she will not be actively terminate user sessions. Only the active cluster members (and non-failover) will do.

  • ASA 5520's active / standby, do not sync AnyConnect Profles

    I'm working on two ASA 5520 configuration in a configuration active / standby.  I have almost all the same between the two units for AnyConnect work waiting for both of the following:

    AnyConnect Client profiles

    AnyConnect Client software

    If I download the software manually to the standby unit I get warning against them are not synchronized, and on the active unit if I do a 'writing' standby does not copy the profile or the software.  Anyone has any ideas on this?

    Thank you

    Dan

    Hello

    Bug CSCsr31403

    When you configure the ASA in a failover pair, you must manually copy the AnyConnect and CSD images for the primary and the secondary ASA.   You must also do the same for the Anyconnect profile file if you use it.

    Either force the ASA shall become active and copy the files to the new ASA assets using ASDM or copy files directly from the console ASA ensures using tftp or ftp.

    Kind regards

    Note the useful messages

    Julio

  • ASA (Active standby) site-to-Site VPN Question

    Hello

    I had the question as below

    Site A - 1 unit of VPN Netscreen firewall

    Site B - 2 units of ASA VPN firewall

    I'm trying to set up a VPN from Site to Site, but a problem with the configuration of the active standby.

    Initially, I tried Site A 1 unit Netscreen and Site B 1 unit ASA vpn site-to-site. There's no problem.

    but joins another ASA at site B and configure it as active / standby then I saw a few questions that I need help from here

    Things that confuse me.

    (1) do I need to use 2 public IP address on the SAA? (public IP for assets and the other a public IP ensures IP. it seems like a waste of the public IP address.)

    (2) link failover and dynamic failover can be configured on the same interface?

    Please help in this case, configuring VPN from Site to Site with active configuration / standby.

    just to add to this,

    just be careful when you dedicate an interface for dynamic failover, make sure that it is the highest capacity, or at least the same ability as an interface offers th

    so if you use concert for passing traffic interface uses a concert for dynamic failover port, several times we saw people using the management for steful interface when they ports of concert and they run into issues where the dynamic function does not work as expected

    You can read more here

    https://www.Cisco.com/en/us/docs/security/ASA/asa80/configuration/guide/failover.html#wp1051759

  • Cisco ASA active / standby Mac addresses

    Hi all

    Please advise on the underside.

    Say that I have to active / standby. I have two interfaces on each firewall configured as below

    For the primary (active)

    interface GigabitEthernet1 / 0--> Say burned in mac address is 6c41.6bb0.1111
    nameif test1
    security-level 0
    10.1.1.1 IP address 255.255.255.0 ensures 10.1.1.2

    im int 2/0

    Test2 nameif--> Say burned in mac address is 6c41.6aa0.1111
    security-level 0
    10.2.1.1 IP address 255.255.255.0 ensures 10.2.1.2

    For secondary school (currently idle)

    interface GigabitEthernet1 / 0--> Say burned in mac address is 6c41.6bb0.2222
    nameif test1
    security-level 0
    10.1.1.1 IP address 255.255.255.0 ensures 10.1.1.2

    im int 2/0

    Test2 nameif--> Say burned in mac address is 6c41.6aa0.2222
    security-level 0
    10.2.1.1 IP address 255.255.255.0 ensures 10.2.1.2

    According to my understanding of the DOC.

    To transfer traffic, other devices will use the main unit mac address and IP addresses.

    Please consider under the scenario:

    My primary unit has failed and secondary took over as active unit.

    Primary (standby)

    Secondary (active)

    secondary Q1) so now will use the IP address and Mac address as below? Please confirm

    10.1.1.1 & 6c41.6bb0.1111

    10.2.1.1 & 6c41.6aa0.1111

    Q2) I believe that the ip address of the primary (Standby) in aid will be

    10.1.1.2

    10.2.1.2

    It will use what mac addresses? What is the BIA of the secondary unit? Please notify

    Thanks in advance.

    Q1 Yes), IP address and the MAC will be moving to the new active unit so no matter who the network except the switch will notice failover event

    Q2) Yes, primary (watch now) will use IP addresses and MAC addresses available for secondary:

    6C41.6bb0.2222

    6C41.6aa0.2222

    Kind regards.

  • on the stateful failover active / standby

    Hello guys.

    I have two ASA, same model and material. ASA have configured stateful failover active / standby by someone a few years ago. It worked normally until recently and no one changed the configuration. Then the secondary unit can't. Ping between 2 interfaces is ok. Please help me solve this problem.

    on the main site

    interface Management0/0

    STATE failover Interface Description

    management only

    interface GigabitEthernet1/1

    Failover LAN Interface Description

    failover

    primary failover lan unit

    failover lan interface failover GigabitEthernet1/1

    The link with failover Management0/0 status

    failover failover interface ip 172.16.1.1 255.255.255.0 ensures 172.16.1.2

    State of the failover interface ip 172.16.0.1 255.255.255.0 ensures 172.16.0.2

    on the secondary site

    interface Management0/0

    STATE failover Interface Description

    management only

    interface GigabitEthernet1/1

    Failover LAN Interface Description

    output of the show failover on PRIMARY

    Show execution of failover

    failover

    primary failover lan unit

    failover lan interface failover GigabitEthernet1/1

    The link with failover Management0/0 status

    failover failover interface ip 172.16.1.1 255.255.255.0 ensures 172.16.1.2

    State of the failover interface ip 172.16.0.1 255.255.255.0 ensures 172.16.0.2

    See the resumption of F1 #.

    Failover on

    Unit of primary failover

    Failover LAN interface: GigabitEthernet1/1 failover (maximum)

    Frequency of survey unit 1 seconds, 15 seconds holding time

    Survey frequency interface 5 seconds, 25 seconds hold time

    1 political interface

    Monitored 5 256 maximum Interfaces

    Version: Our 8.2 (2), Matt 8.2 (2)

    Last failover to: 08:03:11 ULAST January 1, 2003

    This host: primary: enabled

    Activity time: 5755203 (s)

    slot 0: ASA5550 hw/sw rev (status 2.0/8.2(2)) (upward (Sys)

    Interface Backup2 (10.2.5.1): Normal (pending)

    Internet (202.131.225.90) interface: No link (pending)

    Interface Backup1 (10.3.5.1): Normal (pending)

    The interface server (192.168.227.1): Normal (pending)

    Bank interface (10.20.1.1): Normal (pending)

    Slot 1: rev hw/sw ASA-SSM-4GE-INC (State of 1.0/1.0(0)10) (top)

    Another host: secondary - failed

    Activity time: 0 (s)

    slot 0: ASA5550 hw/sw rev (status 2.0/8.2(2)) (upward (Sys)

    Backup2 (0.0.0.0) interface: no connection (pending)

    Interface (0.0.0.0) Internet: No link (pending)

    Interface (0.0.0.0) Backup1: Normal (pending)

    The interface server (0.0.0.0): Normal (pending)

    Bank interface (0.0.0.0): Normal (pending)

    Slot 1: rev hw/sw ASA-SSM-4GE-INC (State of 1.0/1.0(0)10) (top)

    Failover stateful logical Update Statistics

    Link: State Management0/0 (top)

    Stateful Obj xmit rcv rerr xerr

    General 76184539 0 767513 6

    sys cmd 767328 0 767326 1

    up time         0          0          0          0

    RPC services 0 0 0 0

    25878669 0 11 5 TCP Conn

    Conn UDP 40545710 0 40 0

    ARP 8987688 0 136 tbl 0

    Xlate_Timeout 0 0 0 0

    Tbl IPv6 ND 0 0 0 0

    VPN IKE upd 1140 0 0 0

    VPN IPSEC upd 4004 0 0 0

    VPN CTCP upd 0 0 0 0

    VPN SDI upd 0 0 0 0

    VPN DHCP upd 0 0 0 0

    SIP session 0 0 0 0

    Logical update queue information

    Heart Max Total

    Q: recv 0 7 6522961

    Xmit Q: 0 34 106685671

    output of the secondary recovery

    See the resumption of F1 #.

    Failover on

    Secondary failover unit

    Failover LAN interface: GigabitEthernet1/1 failover (maximum)

    Frequency of survey unit 1 seconds, 15 seconds holding time

    Survey frequency interface 5 seconds, 25 seconds hold time

    1 political interface

    Monitored 5 256 maximum Interfaces

    Version: Our 8.2 (2), Matt 8.2 (2)

    Last failover at: 03:36:23 ULAST December 15, 2013

    This host: secondary - failed

    Activity time: 0 (s)

    slot 0: ASA5550 hw/sw rev (status 2.0/8.2(2)) (upward (Sys)

    Backup2 (0.0.0.0) interface: no connection (pending)

    Interface (0.0.0.0) Internet: No link (pending)

    Interface (0.0.0.0) Backup1: Normal (pending)

    The interface server (0.0.0.0): Normal (pending)

    Bank interface (0.0.0.0): Normal (pending)

    Slot 1: rev hw/sw ASA-SSM-4GE-INC (State of 1.0/1.0(0)10) (top)

    Another host: primary: enabled

    Activity time: 5743217 (s)

    slot 0: ASA5550 hw/sw rev (status 2.0/8.2(2)) (upward (Sys)

    Interface Backup2 (10.2.5.1): Normal (pending)

    Internet (202.131.225.90) interface: No link (pending)

    Interface Backup1 (10.3.5.1): Normal (pending)

    The interface server (192.168.227.1): Normal (pending)

    Bank interface (10.20.1.1): Normal (pending)

    Slot 1: rev hw/sw ASA-SSM-4GE-INC (State of 1.0/1.0(0)10) (top)

    Failover stateful logical Update Statistics

    Link: State Management0/0 (top)

    Stateful Obj xmit rcv rerr xerr

    General 765518 0 35843181 874

    sys cmd 765518 0 765516 0

    up time         0          0          0          0

    RPC services 0 0 0 0

    TCP 0 0 12671303 80 Conn

    UDP 0 0 13432853 133 Conn

    ARP 0 0 8968384 661 tbl

    Xlate_Timeout 0 0 0 0

    Tbl IPv6 ND 0 0 0 0

    VPN IKE 0 0 1137 upd 0

    VPN IPSEC 0 0 3988 upd 0

    VPN CTCP upd 0 0 0 0

    VPN SDI upd 0 0 0 0

    VPN DHCP upd 0 0 0 0

    SIP session 0 0 0 0

    Logical update queue information

    Heart Max Total

    Q: recv 0 9 72011189

    Xmit Q: 0 1 765518

    You have a couple no link on your high school as well as a message no link on your primary.

    Backup2 (0.0.0.0) interface: no connection (pending)

    Interface (0.0.0.0) Internet: No link (pending)

    I recommend that you check these cables.  Don't forget that if you changed the default configuration, a failure of the single, or problems of connectivity even interface between an interface on the two ASAs fail.

    If this does not help, try entering the command interface of the monitor for the interfaces.

    --
    Please do not forget to rate and choose a good answer

  • What is the procedure for upgrading Thunderbird ESR 17.0.7 at 31.6 on Mac OSX 10.10.2?

    What is the procedure for upgrading from Thunderbird ESR 17.0.7 at 31.6 (last public version) on Mac OSX 10.10.2?

    Is it as simple as install new version and then run to see all local folders and my email and its folders from IMAP to my company as before the upgrade?

    Thank you

    Create a full backup of your Thunderbird profiles folder.
    Uninstall the old version of ESR.
    Download the latest version from https://www.mozilla.org/en-US/thunderbird/all.html and install it.

  • Is it necessary to buy two packs of licenses to set up a cluster active / standby HA with two units of TZ300?

    I need a cluster active / standby and I think I will need to buy two devices and only CGSS. Am I wrong?
    Why there is no TZ300 HA Unit regarding the unity of TZ500 HA and TZ600 HA unit?

    Thank you

    Angelo

    Yes, you are going to have to buy two devices and licenses only to your main unit. The only reason why there are TZ500 and 600 HA units because generally these are units that especially customer implement an HA pair because of the power they have.

    A TZ300 and 400 are wanted over a smaller model of business that usually gives rise to not have an HA pair so their isn't a specific unit of HA.

    These HA units are not different from any other unit, they are simply locked as part of a wise pair HA license.

    Thank you
    Ben Davis
    Reference Dell SonicWALL
    #Iwork4Dell

  • Safe way to restart the pair active / standby

    Hello

    I need to reboot my ASA5520. We have a pair of active / standby and I want to make sure they come in playing well and not in a fierce struggle.

    Any advice on how to reload these machines and optimize operating times?

    Thank you

    Pedro

    Pedro

    If you are not bothered in regards to he who becomes primary then simply pick one, reboot, wait until it has developed and then reload it.

    As long as you have properly configured failover, there should be minimal downtime, just the time it takes to switch when you reload.

    If you want to stay as the main primary school, then you need to recharge it first, let it come as standby, then reload the other and the former primary school will now become primary.

    Note that recharge the standby is firstly the best approach simply because you then have only a failover IE. When Eve comes backup and resumes, it's a standby feature then you recharge the primary here will be a failover.

    Jon

  • Upgrade to Cisco ASA 5520 8.2.5 to 9.1.7

    Hello

    I have an upgrade tonight for a customer to upgrade a StandAlone ASA 5520 in version 8.2.5 in 9.1.7. I have the same upgrade week next to the same client for a failover pair.

    I already have this kind of process of 8.2.x upgrade to 9.1.x so I know the entire process, since I have to take a first step 8.2.5 8.4.6 then 9.1.7. In addition this customer has no statement of Nat therefore normally an easy process.

    But today during my routine to prepare for the upgrade (I prefer to make a double or triple check before) I found this bug:

    https://BST.cloudapps.Cisco.com/bugsearch/bug/CSCuh19234;JSESSIONID=0A69...

    This bug is fixed in version 8.4.7, and 8.4.6.99. But it is not recommended by the upgrade process for a 8.2.5 to 8.4.7 jump and I can not find the 8.4.6.99 version.

    I don't want to have any problems during my upgrade with something I can avoid.

    As I said I already have this updated in the past without any problem and with a more complex configuration.

    Has anyone as a return to this process for the last months? Should I do an extra step? (before first 8.2.5 to 8.4.5 8.4.6 or 8.4.7)

    Thank you in advance for your answer.

    There are a few incidents reported for ASA 5520 8.2.5 hit this defect running.

    You can go for an extra for 8.4.x upgrade as you mentioned to avoid default we can't say for sure if you will encounter this situation or not.  8.4.6.99 can be a picture of development so be unavailable unless you want to call TAC and confirm or obtain any other image in 8.4.x train.
    Maybe add another upgrade code can't hurt as that hit the bug.

    Kind regards
    Dinesh Moudgil

    PS Please rate helpful messages.

  • Active / standby ASR9000v ICL

    Hello world

    After reviewing the documentation for the 9000v, I wonder if it is possible to configure the following scenario without using nV Edge. I have a pair of ASR9912 that are configured as standalone units. We received 3 ASR9000v which we configured in a scenario of the active / standby as part of a requirement of the customer.

    There is a pattern in this link: https://supportforums.cisco.com/document/9868421/asr9000xr-using-satelli... that shows the scenario, but it seems like a VSS deployment. In the same document, section 13 describes a Dual-host configuration. I wonder if that's what I'm looking for. Interfaces GigE on the system of 'sleep' will be in a break state? I'd be worried about some conflicts.

    I'm not the second 9912 upward and going until mid-January because of the power and the grid space, so I can't test until then.

    Has anyone successfully deployed this scenario without using nV Edge?

    Thank you.

    -Dominique

    DOM,

    We prefer that you evaluate advanced bifocals, which is a new feature. You will not need to use NV EDGE and we are actually calling customers of this technology to something more standards based. Take a look at the following:

    http://www.Cisco.com/c/en/us/TD/docs/routers/asr9000/software/asr9k_r5-3...

    Concerning

    Eddie.

  • What is the procedure of upgrading since version 7.1 of CUCM (MCS Server) call manager to version 10.2 of CUCM (on the server of the UCS)

    Hello

    What is the procedure to upgrade the call manager since version 7.1 of CUCM (MCS Server) to version 10.2 of CUCM (on the server of the UCS), please let me know the steps to what would be the backup procedures and upgrades.

    Concerning

    Gerard

    I suggest reading this guide to make sure that you have prepared your environment to support the first 10.x. The link below also contains the path to upgrade to 10.0 (1).

    One of the ways to do this is:

    1 / apply cooling cop upgrade file on all servers in the cluster.

    2 / upgrade the cluster to 8.6 (2). Make a backup of the cluster.

    3 / build a cluster of servers 8.6 (2) on the virtual machines and assign them the same host name and the IP address of the cluster hardware. (You may need to keep these on a separate network until turn off hardware machines)

    4 / restoration of the backup of the pile of material on the VM cluster.

    5 / upgrade cluster VM to 10.0 (1).

    http://www.Cisco.com/c/en/us/TD/docs/voice_ip_comm/CUCM/upgrade/10_0_1/C...

  • Help about LAN-based failover active / standby on pix 7.0

    Hello

    I wonder why my status active / standby faiover having to wait. And when I do sh failover state he failed on Hello not hear talk of companion to the standby state (see attachment)

    Failover on

    Status of cable: n/a - active LAN failover

    Unit of primary failover

    Failover LAN Interface: failover GigabitEthernet1 (top)

    Frequency of survey unit 1 seconds, 3 seconds hold time

    Interface frequency of survey 15 seconds

    1 political interface

    Watched 3 Interfaces maximum 250

    failover replication http

    Last failover to: 02:39:25 MYT on April 15, 2006

    This host: primary: enabled

    Activity time: 184985 (s)

    Interface inside (10.103.1.15): Normal (pending)

    Interface to the outside (210.187.51.2): Normal (pending)

    DMZ (210.187.51.81) of the interface: Normal (pending)

    Another host: secondary - ready Standby

    Activity time: 0 (s)

    Interface (0.0.0.0) inside: Normal (pending)

    Interface (0.0.0.0) outdoors: Normal (pending)

    Interface (0.0.0.0) dmz: Normal (pending)

    Failover stateful logical Update Statistics

    Link: failover GigabitEthernet1 (top)

    Stateful Obj xmit rcv rerr xerr

    101718 General 0 419 0

    sys cmd 419 0 419 0

    time 0 0 0 0

    RPC services 0 0 0 0

    Conn 74719 TCP 0 0 0

    Conn 21655 UDP 0 0 0

    ARP tbl 4928 0 0 0

    Xlate_Timeout 0 0 0 0

    VPN IKE upd 0 0 0 0

    VPN IPSEC upd 0 0 0 0

    VPN CTCP upd 0 0 0 0

    VPN SDI upd 0 0 0 0

    VPN DHCP upd 0 0 0 0

    Logical update queue information

    Heart Max Total

    Q: recv 0 2 419

    Xmit Q: 0 2 104936

    Is there something wrong with my setup?

    I use active LAN failover / standby.

    I am attached to my firewall configuration, failover, failover state sh sh and sh story of failover.

    looking at your configs... IP addresses for the rescue unit are missing... It should read something Central this:

    interface Ethernet0

    nameif outside

    IP 209.165.201.1 255.255.255.224 watch 209.165.201.2

Maybe you are looking for

  • Minimize, maximize and Quit buttons appear in black

    Windows 7, open Firefox by using the icon on desktop/toolbar the minimize, maximize and Quit buttons are not displayed correctly. However, when you open a link to a mail electronics (client Thunderbird) buttons to minimize, maximizes and Quit appear

  • Are there examples of DataSocket up-to-date for Labwindows/CVI

    I am in the process of taking data to return data from test equipment using WiFi.  I want to use DataSocket, but all the examples I found for Labwindows/CVI are using data functions API DataSocket.  Are there more recent examples available to show ho

  • Aspire E1 - 571 does not start

    When I press the button power button blue led lights for the duration of pressure on it, but nothing is actually happening with the laptop itself, is not even a murmur of activity. If I leave it alone for a few minutes, that's going to start randomly

  • Rocket new 8 GB not recognized by Windows

    My new 8 GB is not fully recognised on two different Windows computers. I've tried different USB settings (several times for each) I've tried different USB ports Hold the off button for 20 seconds Tried different ways to connect (USB first and then t

  • Email stuck in Outbox that go to more than one person - Windows 8

    I try to send an email to 12 people, but the lands of e-mail in the Outbox.  I can send an email to me at my e-mail address electronic outlook.  I have a ultra book of lenovo.