Cisco – Preempt in ASA a/s fail over

ciscocisco-asafailoverfirewall

As there is no option for preempt in ASA active/standby configuration, does anyone have a suggestion for a workaround to confirm that primary ASA will always be active when it is up?

Best Answer

According to Cisco, there are three ways for the formerly Active, now Standby, primary unit to again become Active:

  1. Active unit failed (power or hardware)
  2. Failover link failed at startup
  3. Interface failure on active unit above threshold

You may be able to do something with an EEM script to fail an interface on the now Active secondary unit when the now Standby primary unit comes back up, and then restore the failed interface after the unit returns to Standby. This is a real kludge because this is not the design for Active/Standby.