Loading...
Loading...
Scenario Description Result 1 Disabling the pri/act firewall in Chassis Manager results in a complete outage 2 Rebooting the pri/act firewall from CLI an outage is experienced until firewall is finished with it's reboot 3 Rebooting the sec/act firewall from the CLI results in a short outage (missing a couple of pings) 4 Reboot of the pri/sta firewall from CLI there is an outage starting from state "Cold Start" and "App Sync" until firewall finishes rebooting
The software on the 4115 chassis is 2.14(1.143), the FMC and FTD's are running 7.4.2.1. We also did the same tests on 2 Firepower 3110 units on 7.4.2.1 and 7.6.0 and the results are the same.
Before disabling the instance from FCM, ensure that the HA unit is in Standby state. If the unit is currently Active, first switch it to Standby. Once the unit is in Standby, use the CLISH prompt to temporarily suspend high-availability: > configure high-availability disable Disable high-availability configuration resume Resume temporarily suspended high-availability configuration suspend Temporarily suspend high-availability configuration > configure high-availability suspend This step ensures that the peer unit remains Active and continues to handle traffic, thereby preventing any potential outage due to a split-brain scenario.
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.