<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A/S ASAs with a 3850 stack in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3326771#M1064183</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;I am having some issues in an ASA active/standby pair (5516, 9.8), connected to a 3850 stack. The primary ASA is connected to switch 1 of the stack, the secondary to switch 2.&lt;/P&gt;
&lt;P&gt;What I am facing are the interfaces on the secondary ASA being in a FAILED state, except one interface (inside).&lt;/P&gt;
&lt;P&gt;I have checked all that I could, the cables are OK, the config on the switchports are the same.&lt;/P&gt;
&lt;P&gt;Below are some show outputs, and I have included a debug from the primary unit while shut/no shut the switchports connected to the secondary ASA.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show run fail&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER GigabitEthernet1/8&lt;BR /&gt;failover link FAILOVER GigabitEthernet1/8&lt;BR /&gt;failover interface ip FAILOVER 10.254.254.253 255.255.255.252 standby 10.254.254.254&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail&lt;BR /&gt;Failover On &lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: FAILOVER GigabitEthernet1/8 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 4 of 160 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.8(1), Mate 9.8(1)&lt;BR /&gt;Serial Number: Ours JAD21360B9E, Mate JAD213401KV&lt;BR /&gt;Last Failover at: 13:13:57 CEST Jan 22 2018&lt;BR /&gt; This host: Primary - Active &lt;BR /&gt; Active time: 1390912 (sec)&lt;BR /&gt; slot 1: ASA5516 hw/sw rev (3.0/9.8(1)) status (Up Sys)&lt;BR /&gt; Interface inside (192.168.20.251): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.200): Normal (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.253): Normal (Waiting)&lt;BR /&gt; Interface outside (a.b.c.70): Normal (Waiting)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0.4-85) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0.4-85, Up, (Not-Monitored)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0.4-85) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0.4-85, Up, (Not-Monitored)&lt;BR /&gt; Other host: Secondary - Failed &lt;BR /&gt; Active time: 0 (sec)&lt;BR /&gt; slot 1: ASA5516 hw/sw rev (3.0/9.8(1)) status (Up Sys)&lt;BR /&gt; Interface inside (192.168.20.250): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.201): Failed (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.254): Failed (Waiting)&lt;BR /&gt; Interface outside (a.b.c.69): Failed (Waiting)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0-362) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0-362, Up, (Not-Monitored)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0-362) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0-362, Up, (Not-Monitored)&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : FAILOVER GigabitEthernet1/8 (up)&lt;BR /&gt; Stateful Obj xmit xerr rcv rerr &lt;BR /&gt; General 59828407 0 185453 0 &lt;BR /&gt; sys cmd 185453 0 185453 0 &lt;BR /&gt; up time 0 0 0 0 &lt;BR /&gt; RPC services 0 0 0 0 &lt;BR /&gt; TCP conn 35147229 0 0 0 &lt;BR /&gt; UDP conn 18573036 0 0 0 &lt;BR /&gt; ARP tbl 5920132 0 0 0 &lt;BR /&gt; Xlate_Timeout 0 0 0 0 &lt;BR /&gt; IPv6 ND tbl 0 0 0 0 &lt;BR /&gt; VPN IKEv1 SA 594 0 0 0 &lt;BR /&gt; VPN IKEv1 P2 643 0 0 0 &lt;BR /&gt; VPN IKEv2 SA 0 0 0 0 &lt;BR /&gt; VPN IKEv2 P2 0 0 0 0 &lt;BR /&gt; VPN CTCP upd 0 0 0 0 &lt;BR /&gt; VPN SDI upd 0 0 0 0 &lt;BR /&gt; VPN DHCP upd 0 0 0 0 &lt;BR /&gt; SIP Session 0 0 0 0 &lt;BR /&gt; SIP Tx 0 0 0 0 &lt;BR /&gt; SIP Pinhole 0 0 0 0 &lt;BR /&gt; Route Session 187 0 0 0 &lt;BR /&gt; Router ID 0 0 0 0 &lt;BR /&gt; User-Identity 1133 0 0 0 &lt;BR /&gt; CTS SGTNAME 0 0 0 0 &lt;BR /&gt; CTS PAC 0 0 0 0 &lt;BR /&gt; TrustSec-SXP 0 0 0 0 &lt;BR /&gt; IPv6 Route 0 0 0 0 &lt;BR /&gt; STS Table 0 0 0 0&lt;/P&gt;
&lt;P&gt;Logical Update Queue Information&lt;BR /&gt; Cur Max Total&lt;BR /&gt; Recv Q: 0 7 185457&lt;BR /&gt; Xmit Q: 0 30 60746844&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail descriptor &lt;BR /&gt;inside send: 00020101ffff0000 receive: 00020101ffff0000&lt;BR /&gt;transf send: 000203010f000000 receive: 000203010f000000&lt;BR /&gt;telemed send: 00020301c8000000 receive: 00020301c8000000&lt;BR /&gt;outside send: 00020401ffff0000 receive: 00020401ffff0000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail his&lt;BR /&gt;==========================================================================&lt;BR /&gt;From State To State Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;13:13:54 CEST Jan 22 2018&lt;BR /&gt;Not Detected Negotiation No Error&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Negotiation Just Active No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Just Active Active Drain No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Active Drain Active Applying Config No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Active Applying Config Active Config Applied No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Active Config Applied Active No Active unit found&lt;/P&gt;
&lt;P&gt;==========================================================================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail int&lt;BR /&gt; interface FAILOVER GigabitEthernet1/8&lt;BR /&gt; System IP Address: 10.254.254.253 255.255.255.252&lt;BR /&gt; My IP Address : 10.254.254.253&lt;BR /&gt; Other IP Address : 10.254.254.254&lt;BR /&gt; &lt;BR /&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail state&lt;/P&gt;
&lt;P&gt;State Last Failure Reason Date/Time&lt;BR /&gt;This host - Primary&lt;BR /&gt; Active None&lt;BR /&gt;Other host - Secondary&lt;BR /&gt; Failed Ifc Failure 14:43:19 CEST Feb 7 2018&lt;BR /&gt; inside: Failed&lt;BR /&gt; transf: Failed&lt;BR /&gt; telemed: Failed&lt;BR /&gt; outside: Failed&lt;/P&gt;
&lt;P&gt;====Configuration State===&lt;BR /&gt; Sync Done&lt;BR /&gt;====Communication State===&lt;BR /&gt; Mac set&lt;BR /&gt; &lt;BR /&gt;###############################################################################&lt;BR /&gt; &lt;BR /&gt;ASA/pri/act# show monitor-interface &lt;BR /&gt; This host: Primary - Active &lt;BR /&gt; Interface inside (192.168.20.251): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.200): Normal (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.253): Normal (Waiting)&lt;BR /&gt; Interface outside (a.b.c.70): Normal (Waiting)&lt;BR /&gt; Other host: Secondary - Failed &lt;BR /&gt; Interface inside (192.168.20.250): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.201): Failed (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.254): Failed (Waiting)&lt;BR /&gt; Interface outside (a.b.c.69): Failed (Waiting)&lt;BR /&gt; &lt;BR /&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Besides the failed interfaces, I can not connect to the secondary unit in any way, even though I can ping the inside interface (on the primary unit the inside interface is for management).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Could the stack be causing issues?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:18:18 GMT</pubDate>
    <dc:creator>Boris Simunko</dc:creator>
    <dc:date>2020-02-21T15:18:18Z</dc:date>
    <item>
      <title>A/S ASAs with a 3850 stack</title>
      <link>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3326771#M1064183</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;I am having some issues in an ASA active/standby pair (5516, 9.8), connected to a 3850 stack. The primary ASA is connected to switch 1 of the stack, the secondary to switch 2.&lt;/P&gt;
&lt;P&gt;What I am facing are the interfaces on the secondary ASA being in a FAILED state, except one interface (inside).&lt;/P&gt;
&lt;P&gt;I have checked all that I could, the cables are OK, the config on the switchports are the same.&lt;/P&gt;
&lt;P&gt;Below are some show outputs, and I have included a debug from the primary unit while shut/no shut the switchports connected to the secondary ASA.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show run fail&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER GigabitEthernet1/8&lt;BR /&gt;failover link FAILOVER GigabitEthernet1/8&lt;BR /&gt;failover interface ip FAILOVER 10.254.254.253 255.255.255.252 standby 10.254.254.254&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail&lt;BR /&gt;Failover On &lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: FAILOVER GigabitEthernet1/8 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 4 of 160 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.8(1), Mate 9.8(1)&lt;BR /&gt;Serial Number: Ours JAD21360B9E, Mate JAD213401KV&lt;BR /&gt;Last Failover at: 13:13:57 CEST Jan 22 2018&lt;BR /&gt; This host: Primary - Active &lt;BR /&gt; Active time: 1390912 (sec)&lt;BR /&gt; slot 1: ASA5516 hw/sw rev (3.0/9.8(1)) status (Up Sys)&lt;BR /&gt; Interface inside (192.168.20.251): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.200): Normal (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.253): Normal (Waiting)&lt;BR /&gt; Interface outside (a.b.c.70): Normal (Waiting)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0.4-85) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0.4-85, Up, (Not-Monitored)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0.4-85) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0.4-85, Up, (Not-Monitored)&lt;BR /&gt; Other host: Secondary - Failed &lt;BR /&gt; Active time: 0 (sec)&lt;BR /&gt; slot 1: ASA5516 hw/sw rev (3.0/9.8(1)) status (Up Sys)&lt;BR /&gt; Interface inside (192.168.20.250): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.201): Failed (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.254): Failed (Waiting)&lt;BR /&gt; Interface outside (a.b.c.69): Failed (Waiting)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0-362) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0-362, Up, (Not-Monitored)&lt;BR /&gt; slot 2: SFR5516 hw/sw rev (N/A/6.2.0-362) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.0-362, Up, (Not-Monitored)&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : FAILOVER GigabitEthernet1/8 (up)&lt;BR /&gt; Stateful Obj xmit xerr rcv rerr &lt;BR /&gt; General 59828407 0 185453 0 &lt;BR /&gt; sys cmd 185453 0 185453 0 &lt;BR /&gt; up time 0 0 0 0 &lt;BR /&gt; RPC services 0 0 0 0 &lt;BR /&gt; TCP conn 35147229 0 0 0 &lt;BR /&gt; UDP conn 18573036 0 0 0 &lt;BR /&gt; ARP tbl 5920132 0 0 0 &lt;BR /&gt; Xlate_Timeout 0 0 0 0 &lt;BR /&gt; IPv6 ND tbl 0 0 0 0 &lt;BR /&gt; VPN IKEv1 SA 594 0 0 0 &lt;BR /&gt; VPN IKEv1 P2 643 0 0 0 &lt;BR /&gt; VPN IKEv2 SA 0 0 0 0 &lt;BR /&gt; VPN IKEv2 P2 0 0 0 0 &lt;BR /&gt; VPN CTCP upd 0 0 0 0 &lt;BR /&gt; VPN SDI upd 0 0 0 0 &lt;BR /&gt; VPN DHCP upd 0 0 0 0 &lt;BR /&gt; SIP Session 0 0 0 0 &lt;BR /&gt; SIP Tx 0 0 0 0 &lt;BR /&gt; SIP Pinhole 0 0 0 0 &lt;BR /&gt; Route Session 187 0 0 0 &lt;BR /&gt; Router ID 0 0 0 0 &lt;BR /&gt; User-Identity 1133 0 0 0 &lt;BR /&gt; CTS SGTNAME 0 0 0 0 &lt;BR /&gt; CTS PAC 0 0 0 0 &lt;BR /&gt; TrustSec-SXP 0 0 0 0 &lt;BR /&gt; IPv6 Route 0 0 0 0 &lt;BR /&gt; STS Table 0 0 0 0&lt;/P&gt;
&lt;P&gt;Logical Update Queue Information&lt;BR /&gt; Cur Max Total&lt;BR /&gt; Recv Q: 0 7 185457&lt;BR /&gt; Xmit Q: 0 30 60746844&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail descriptor &lt;BR /&gt;inside send: 00020101ffff0000 receive: 00020101ffff0000&lt;BR /&gt;transf send: 000203010f000000 receive: 000203010f000000&lt;BR /&gt;telemed send: 00020301c8000000 receive: 00020301c8000000&lt;BR /&gt;outside send: 00020401ffff0000 receive: 00020401ffff0000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail his&lt;BR /&gt;==========================================================================&lt;BR /&gt;From State To State Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;13:13:54 CEST Jan 22 2018&lt;BR /&gt;Not Detected Negotiation No Error&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Negotiation Just Active No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Just Active Active Drain No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Active Drain Active Applying Config No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Active Applying Config Active Config Applied No Active unit found&lt;/P&gt;
&lt;P&gt;13:13:57 CEST Jan 22 2018&lt;BR /&gt;Active Config Applied Active No Active unit found&lt;/P&gt;
&lt;P&gt;==========================================================================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail int&lt;BR /&gt; interface FAILOVER GigabitEthernet1/8&lt;BR /&gt; System IP Address: 10.254.254.253 255.255.255.252&lt;BR /&gt; My IP Address : 10.254.254.253&lt;BR /&gt; Other IP Address : 10.254.254.254&lt;BR /&gt; &lt;BR /&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA/pri/act# show fail state&lt;/P&gt;
&lt;P&gt;State Last Failure Reason Date/Time&lt;BR /&gt;This host - Primary&lt;BR /&gt; Active None&lt;BR /&gt;Other host - Secondary&lt;BR /&gt; Failed Ifc Failure 14:43:19 CEST Feb 7 2018&lt;BR /&gt; inside: Failed&lt;BR /&gt; transf: Failed&lt;BR /&gt; telemed: Failed&lt;BR /&gt; outside: Failed&lt;/P&gt;
&lt;P&gt;====Configuration State===&lt;BR /&gt; Sync Done&lt;BR /&gt;====Communication State===&lt;BR /&gt; Mac set&lt;BR /&gt; &lt;BR /&gt;###############################################################################&lt;BR /&gt; &lt;BR /&gt;ASA/pri/act# show monitor-interface &lt;BR /&gt; This host: Primary - Active &lt;BR /&gt; Interface inside (192.168.20.251): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.200): Normal (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.253): Normal (Waiting)&lt;BR /&gt; Interface outside (a.b.c.70): Normal (Waiting)&lt;BR /&gt; Other host: Secondary - Failed &lt;BR /&gt; Interface inside (192.168.20.250): Normal (Monitored)&lt;BR /&gt; Interface transf (10.220.64.201): Failed (Waiting)&lt;BR /&gt; Interface telemed (192.168.200.254): Failed (Waiting)&lt;BR /&gt; Interface outside (a.b.c.69): Failed (Waiting)&lt;BR /&gt; &lt;BR /&gt;###############################################################################&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Besides the failed interfaces, I can not connect to the secondary unit in any way, even though I can ping the inside interface (on the primary unit the inside interface is for management).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Could the stack be causing issues?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3326771#M1064183</guid>
      <dc:creator>Boris Simunko</dc:creator>
      <dc:date>2020-02-21T15:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: A/S ASAs with a 3850 stack</title>
      <link>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3327383#M1064187</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All we have to ensure is that the interfaces- inside, dmz etc are connected in their specific vlans on the stack with portfast enabled on the interfaces.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the switch port configuration to ensure we have correct config and ports are up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to ping from ASA active to standby ip address and vice versa and see if that works. Its like 2 machines connected to the switch in same vlan.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if the switch has mac entry registered for both interfaces in same vlans.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 10:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3327383#M1064187</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-02-08T10:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: A/S ASAs with a 3850 stack</title>
      <link>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3327435#M1064191</link>
      <description>&lt;P&gt;&lt;SPAN&gt;so...... I was checking things again and realized the customer connected the cables on the secondary unit wrong &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Failover is now OK, and I can ping the interfaces on the standby unit, but I am still unable to ASDM into it&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;EDIT: all is working fine now!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 13:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-s-asas-with-a-3850-stack/m-p/3327435#M1064191</guid>
      <dc:creator>Boris Simunko</dc:creator>
      <dc:date>2018-02-08T13:49:08Z</dc:date>
    </item>
  </channel>
</rss>

