Cisco ASA
HA/Redundancy
Manual Failover
Manually failover a group to the peer firewall:
admin# changeto system show failover failover active group 2
Move Context
Move context from group 2 to group 1:
Note: All groups must be on same firewall before you can move a context to another group.
admin# changeto system# failover active group 2(this fails group 2 traffic over to this firewall)# conf t(config)# context fw02(config-ctx)# join-failover-group 1(config-ctx)# end# wr mem# no failover active group 2(this fails group 2 contexts back to other firewall)
VPN
Debug
Debug Specific Peer
# debug crypto condition peer 1.1.1.1
# debug crypto ikev2 protocol 127
Stop All Debugs
# undebug all