66-3
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter66 Configuring Active/Standby Failover
Information About Active/Standby Failover
Note On the standby unit, the configuration exists only in running memory. To save the configuration to the
flash memory on the standby unit, choose File > Save Running Configuration to Flash. Startup
configurations saved on external servers are accessible from either unit over the network and do not need
to be saved separately for each unit. Alternatively, you can copy the contexts on disk from the active unit
to an external server, and then copy them to disk on the standby unit, where they become available when
the unit reloads.
Command Replication
Command replication always flows from the active unit to the standby unit. As you apply your changes
to the active unit in ASDM, the associated commands are sent across the failover link to the standby unit.
You do not have to save the active configuration to flash memory to replicate the commands.
Table66-1 lists the commands that are and are not replicated to the standby unit.
Note Changes made on the standby unit are not replicated to the active unit. If you enter a command on the
standby unit, the ASA displays the message **** WARNING **** Configuration Replication is NOT
performed from Standby unit to Active unit. Configurations are no longer synchronized.
This message appears even when you enter many commands that do not affect the configuration.
Replicated commands are stored in the running configuration. To save replicated commands to the flash
memory on the standby unit, choose File > Save Running Configuration to Flash.
Note Standby Failover does not replicate the following files and configuration components:
AnyConnect images
CSD images
ASA images
Table66-1 Command Replication
Command Replicated to the Standby Unit Commands Not Replicated to the Standby Unit
All configuration commands except for mode,
firewall, and failover lan unit
All forms of the copy command except for copy
running-config startup-config
copy running-config startup-config all forms of the write command except for write
memory
delete crypto ca server and associated sub commands
mkdir debug
rename failover lan unit
rmdir firewall
write memory mode
show
terminal pager and pager