Cisco ASA: Difference between revisions
Line 13: | Line 13: | ||
''Note: All groups must be on same firewall before you can move a context to another group.'' | ''Note: All groups must be on same firewall before you can move a context to another group.'' | ||
admin# changeto system | |||
# failover active group 2 | |||
# conf t | |||
(config)# context fw02 | |||
(config-ctx)# join-failover-group 1 | |||
(config-ctx)# end | |||
# wr mem | |||
# no failover active group 2 | |||
=VPN= | =VPN= |
Revision as of 20:21, 21 January 2025
HA/Redundancy
Manual Failover
Manually failover a group to the peer firewall:
admin# changeto system show failover failover active group 2
Move Context
Move context from group 2 to group 1:
Note: All groups must be on same firewall before you can move a context to another group.
admin# changeto system # failover active group 2 # conf t (config)# context fw02 (config-ctx)# join-failover-group 1 (config-ctx)# end # wr mem # no failover active group 2
VPN
Debug
Debug Specific Peer
# debug crypto condition peer 1.1.1.1
# debug crypto ikev2 protocol 127
Stop All Debugs
# undebug all