Manually Intervening in Failover

When the firewalls in a failover pair detect a failure and take action, they do not automatically revert to their original failover roles. For example, if the primary firewall is active and then fails, it is marked as failed, and the secondary firewall takes over the active role. After the primary unit is repaired and returned to service, it does not automatically reclaim the active role (unless it has been configured to preempt active control).

You might occasionally find that you need to manually intervene in the failover process to force a role change or to reset a failover condition. The commands discussed in the following sections should be used from configuration mode in single-context mode and in the system execution space in multiple-context mode.

Forcing a Role Change

Ordinarily, the firewalls fail over to each other automatically, without any intervention. However, they do not automatically fail back to their original roles. If for some reason you need to force one unit to become active again, you can use the following privileged EXEC command:

You can also force a unit into standby mode with the no failover active command.

With active-active failover, you can specify the failover group (1 or 2) that will become active. For example, suppose the secondary firewall should be standby for failover group 1 and active for failover group 2. After a failure, it ends up in standby mode for both failover groups, as shown in the following output:

Firewall# show failover Failover On

Cable status: N/A - LAN-based failover enabled Failover unit Primary

Failover LAN Interface: Failover Ethernet0/2 (up) Unit Poll frequency 3 seconds, holdtime 9 seconds Interface Poll frequency 15 seconds Interface Policy 2

Monitored Interfaces 3 of 250 maximum Group 1 last failover at: 10:29:18 EST Jan 30 2005 Group 2 last failover at: 16:18:28 EST Mar 9 2005 This host: Secondary

Group 1 State: Standby Ready

Active time: 3311601 (sec) Group 2 State: Standby Ready

Active time: 3304092 (sec)

To restore the secondary unit to the active role for failover group 2, you could take two different approaches:

• Force the primary unit (currently active) into the standby role by using the no failover active group 2 command

• Force the secondary unit (currently standby) into the active role by using the failover active group 2 command

Resetting a Failed Firewall Unit

If a firewall has been marked as failed but has been repaired or its connectivity restored, you might have to manually "unfail" it or reset its failover role. You can use the following privileged EXEC command:

Firewall# failover reset [group {1 | 2}]

You can use this command on either the active or failed unit. If it is issued on the active unit, the command is replicated to the failed unit, and only that unit's state is reset. In active-active failover, you can add the group keyword and failover group number for the firewall role to be reset.

Reloading a Hung Standby Unit

Sometimes, an active and standby firewall can communicate over a failover connection but cannot synchronize their failover operation. In this case, you can manually force the standby unit to reload and reinitialize its failover role with the following command:

Firewall# failover reload-standby

After the reload, it should resynchronize with the active unit. Executing Commands on a Failover Peer

Although two firewalls can be configured as a failover pair, they still support their own administrative sessions independently. For example, you can connect to the active unit and enter commands, make configuration changes, and so on. The same is true of the standby unit, where you can connect and do everything except make configuration changes.

Sometimes you might find yourself connected to one unit when you would like to do something on the other unit. Normally you would have to open up an administrative connection to the other unit and enter your commands there. Beginning with ASA 8.0(1), you can open a single session and enter commands that are passed to the failover peer and evaluated there.

Use the following EXEC command to send a command string to the appropriate failover unit:

Firewall# failover exec {active | standby | mate} cmd string

Regardless of the unit to which you are connected, you can send a command line, cmd_string, to any of the following failover pair units:

• active— The command is sent to the current active unit, where it is executed and also replicated to the standby unit.

• standby— The command is sent to the current standby unit, where it is executed; it is not replicated to the active unit.

• mate— The command is sent to the mate or peer of the unit, where the command is entered.

For example, suppose you are connected to the active unit, where you can display its activation key with the show activation-key command. Then, without opening a second connection to the standby unit, you can see the standby unit's flash file system by sending it the same command, too, as in the following example:

Code View: Scroll / Show All

Firewall# show activation-key Serial Number: 848020184

Running Activation Key: 0x7111c56d 0x689a94fa 0xa4f0b064 0x910c0474 0xcf36c2ba

Licensed features for this platform:

Maximum Physical Interfaces

Maximum VLANs

Inside Hosts

Failover

Continue reading here: Manually Upgrading a Failover Pair

Was this article helpful?

0 0

Readers' Questions

  • dewayne marion
    What is the command to forcefully activate a secondary firewall to become an active firewall?
    1 month ago
  • The command to forcefully activate a secondary firewall to become an active firewall is "failover active".