14-31
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Chapter 14 Configuring Failover
Configuring Failover
hostname(config)# failover lan enable
Step 2 Define the failover interface. Use the same settings as you used for the primary unit:
a. Specify the interface to be used as the failover interface:
hostname(config)# failover lan interface if_name phy_if
The if_name argument assigns a logical name to the interface specified by the phy_if argument. The
phy_if argument can be the physical port name, such as Ethernet1, or a previously created
subinterface, such as Ethernet0/2.3. On the ASA 5505 adaptive security appliance, the phy_if
specifies a VLAN.
b. Assign the active and standby IP address to the failover link:
hostname(config)# failover interface ip if_name ip_addr mask standby ip_addr
Note Enter this command exactly as you entered it on the primary unit when you configured the
failover interface.
The standby IP address must be in the same subnet as the active IP address. You do not need to
identify the standby address subnet mask.
c. Enable the interface:
hostname(config)# interface phy_if
hostname(config-if)# no shutdown
Step 3 (Optional) Designate this unit as the secondary unit:
hostname(config)# failover lan unit secondary
Note This step is optional because by default units are designated as secondary unless previously
configured otherwise.
Step 4 Enable failover:
hostname(config)# failover
After you enable failover, the active unit sends the configuration in running memory to the standby unit.
As the configuration synchronizes, the messages
Beginning configuration replication: Sending to
mate
and End Configuration Replication to mate appear on the active unit console.
Step 5 After the running configuration has completed replication, enter the following command to save the
configuration to Flash memory:
hostname(config)# copy running-config startup-config
Step 6 If necessary, force any failover group that is active on the primary to the active state on the secondary
unit. To force a failover group to become active on the secondary unit, enter the following command in
the system execution space on the primary unit:
hostname# no failover active group group_id
The group_id argument specifies the group you want to become active on the secondary unit.