<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 firewall keeps testing on one interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3320911#M1014406</link>
    <description>&lt;P&gt;Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a similar problem on my 5510s (ASA Version 9.1(7)16 )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The difference is that mine ASAs are in transparent mode and have 3BVIs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Primary ASA two of the BVIs interfaces are Normal(Monitored) but of them is constantly being tested and Passed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Standby all interfaces looks ok - Normal (Monitored).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These error messages (%ASA-1-105008;&amp;nbsp;%ASA-1-105009) are only appearing when I'm running on the Primary Active. Once I fail them over to Secondary all interfaces are being shown Normal (Monitored). I'm NOT getting the&amp;nbsp;&lt;SPAN&gt;%ASA-1-105005 but ASAs logging this error as Critical (file attached).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can anyone advise please ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2018 14:35:00 GMT</pubDate>
    <dc:creator>layer1981</dc:creator>
    <dc:date>2018-01-29T14:35:00Z</dc:date>
    <item>
      <title>ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3224409#M1014401</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a ASA 5520 firewall as a boarder of our network to one of our client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently, the outside interface of the secondary unit keep testing and keeps pass. I got the email from the firewall a few times a day. there is no obvious network drop as no one complaint and also as it's a secondary unit as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are the emails I got from the firewall every day:&lt;/P&gt;
&lt;P&gt;%ASA-1-105008: (Secondary) Testing Interface outside&lt;BR /&gt;%ASA-1-105005: (Secondary) Lost Failover communications with mate on interface outside&lt;BR /&gt;%ASA-1-105009: (Secondary) Testing on interface outside Passed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to trouble shoot and see why it's happening but I don't know where to start.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the cabling and failover status and all is good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3224409#M1014401</guid>
      <dc:creator>Ge Qu</dc:creator>
      <dc:date>2020-02-21T14:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3224721#M1014402</link>
      <description>&lt;P&gt;Are the interface counters clean? Are the&amp;nbsp;duplex settings set correctly? Are there any log-messages on the outside-switch?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 22:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3224721#M1014402</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-29T22:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3225806#M1014403</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;can you post a &lt;STRONG&gt;show run failover&lt;/STRONG&gt; and &lt;STRONG&gt;show failover output&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;try removing HTTP replication if it's being used.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no failover replication http&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2017 03:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3225806#M1014403</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2017-12-02T03:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3227987#M1014404</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following are the sho run failover and show failover results, why need to disable the http replication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sh run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface fo-link GigabitEthernet0/3&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link fo-link GigabitEthernet0/3&lt;BR /&gt;failover interface ip fo-link&amp;nbsp;x.x.x.x 255.255.255.252 standby&amp;nbsp;x.x.x.y&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sh failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: fo-link GigabitEthernet0/3 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 5 of 160 maximum&lt;BR /&gt;failover replication http&lt;BR /&gt;Version: Ours 8.2(5), Mate 8.2(5)&lt;BR /&gt;Last Failover at: 17:25:07 EDT Mar 30 2017&lt;BR /&gt; This host: Primary - Active&lt;BR /&gt; Active time: 21625335 (sec)&lt;BR /&gt; slot 0: ASA5520 hw/sw rev (1.1/8.2(5)) status (Up Sys)&lt;BR /&gt; Interface xxx (x.x.x.x): Normal&lt;BR /&gt; Interface yyy (x.x.x.x): Normal&lt;BR /&gt; Interface zzz (x.x.x.x): Normal&lt;BR /&gt; Interface aaa (x.x.x.x): Normal (Not-Monitored)&lt;BR /&gt; Interface bbb (x.x.x.x): Normal&lt;BR /&gt; Interface ccc (x.x.x.x): Normal&lt;BR /&gt; slot 1: empty&lt;BR /&gt; Other host: Secondary - Standby Ready&lt;BR /&gt; Active time: 6118 (sec)&lt;BR /&gt; slot 0: ASA5520 hw/sw rev (1.1/8.2(5)) status (Up Sys)&lt;BR /&gt; Interface xxx (x.x.x.x): Normal&lt;BR /&gt; Interface yyy (x.x.x.x): Normal&lt;BR /&gt; Interface zzz (x.x.x.x2): Normal&lt;BR /&gt; Interface aaa (x.x.x.x): Normal (Not-Monitored)&lt;BR /&gt; Interface bbb (x.x.x.x): Normal&lt;BR /&gt; Interface ccc (x.x.x.x): Normal&lt;BR /&gt; slot 1: empty&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : fo-link GigabitEthernet0/3 (up)&lt;BR /&gt; Stateful Obj xmit xerr rcv rerr&lt;BR /&gt; General 1887991115 0 2882776 0&lt;BR /&gt; sys cmd 2882796 0 2882776 0&lt;BR /&gt; up time 0 0 0 0&lt;BR /&gt; RPC services 0 0 0 0&lt;BR /&gt; TCP conn 1446887935 0 0 0&lt;BR /&gt; UDP conn 387137788 0 0 0&lt;BR /&gt; ARP tbl 51082596 0 0 0&lt;BR /&gt; Xlate_Timeout 0 0 0 0&lt;BR /&gt; IPv6 ND tbl 0 0 0 0&lt;BR /&gt; VPN IKE upd 0 0 0 0&lt;BR /&gt; VPN IPSEC upd 0 0 0 0&lt;BR /&gt; VPN CTCP upd 0 0 0 0&lt;BR /&gt; VPN SDI upd 0 0 0 0&lt;BR /&gt; VPN DHCP upd 0 0 0 0&lt;BR /&gt; SIP Session 0 0 0 0&lt;/P&gt;
&lt;P&gt;Logical Update Queue Information&lt;BR /&gt; Cur Max Total&lt;BR /&gt; Recv Q: 0 4 2882776&lt;BR /&gt; Xmit Q: 0 27 1909611057&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 15:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3227987#M1014404</guid>
      <dc:creator>Ge Qu</dc:creator>
      <dc:date>2017-12-06T15:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3227994#M1014405</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The interface counters are clean and no any log messages saying there is an issue and duplex setting is all full&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 15:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3227994#M1014405</guid>
      <dc:creator>Ge Qu</dc:creator>
      <dc:date>2017-12-06T15:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3320911#M1014406</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a similar problem on my 5510s (ASA Version 9.1(7)16 )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The difference is that mine ASAs are in transparent mode and have 3BVIs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Primary ASA two of the BVIs interfaces are Normal(Monitored) but of them is constantly being tested and Passed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Standby all interfaces looks ok - Normal (Monitored).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These error messages (%ASA-1-105008;&amp;nbsp;%ASA-1-105009) are only appearing when I'm running on the Primary Active. Once I fail them over to Secondary all interfaces are being shown Normal (Monitored). I'm NOT getting the&amp;nbsp;&lt;SPAN&gt;%ASA-1-105005 but ASAs logging this error as Critical (file attached).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can anyone advise please ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 14:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3320911#M1014406</guid>
      <dc:creator>layer1981</dc:creator>
      <dc:date>2018-01-29T14:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3336848#M1014407</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why we need to remove&amp;nbsp;failover replication http ?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 19:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3336848#M1014407</guid>
      <dc:creator>Ge Qu</dc:creator>
      <dc:date>2018-02-23T19:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 firewall keeps testing on one interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3391169#M1014408</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like we have got stuck with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone please advise how to fix this weird issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did have to disable sent alert emails because our email box was getting hundreds of emails a day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ge Qu - unless you really have to , do not remove this http replication. Cisco says that "not replicating HTTP sessions increases system performance without causing serious data or connection loss" I'm keeping this still enabled , just in case. Cisco says that replication "could have a negative impact upon system performance" but our performance seems to be ok.&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 11:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-keeps-testing-on-one-interface/m-p/3391169#M1014408</guid>
      <dc:creator>layer</dc:creator>
      <dc:date>2018-05-30T11:21:08Z</dc:date>
    </item>
  </channel>
</rss>

