66-4
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter66 Configuring Active/Standby Failover
Information About Active/Standby Failover
AnyConnect profiles
Local Certificate Authorities (CAs)
ASDM images
Failover Triggers
The unit can fail if one of the following events occurs:
The unit has a hardware failure or a power failure.
The unit has a software failure.
Too many monitored interfaces fail.
You force a failover. (See the “Forcing Failover” section on page66-13.)
Failover Actions
In Active/Standby failover, failover occurs on a unit basis. Even on systems running in multiple context
mode, you cannot fail over individual or groups of contexts.
Table66-2 shows the failover action for each failure event. For each failure event, the table shows the
failover policy (failover or no failover), the action taken by the active unit, the action taken by the
standby unit, and any special notes about the failover condition and actions.
Table66-2 Failover Behavior
Failure Event Policy Active Action Standby Action Notes
Active unit failed (power or
hardware)
Failover n/a Become active
Mark active as
failed
No hello messages are received on
any monitored interface or the
failover link.
Formerly active unit recovers No failover Become standby No action None.
Standby unit failed (power or
hardware)
No failover Mark standby as
failed
n/a When the standby unit is marked as
failed, then the active unit does not
attempt to fail over, even if the
interface failure threshold is
surpassed.
Failover link failed during
operation
No failover Mark failove r
interface as failed
Mark failover
interface as failed
You should restore the failover link
as soon as possible because the
unit cannot fail over to the standby
unit while the failover link is down.
Failover link failed at sta rtup N o failover Mark failover
interface as failed
Become active If the failover link is down at
startup, both units become active.
Stateful Failover link failed No failover No action No action State information becomes out of
date, and sessions are terminated if
a failover occurs.