<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA failover Active/Standby in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180405#M1066457</link>
    <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your responce to my query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We observe Secondary ASA has taken the "Active" role as soon as the Primary unit has failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can able to reach the Firewall from LAN and able to ping the public Networks from Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, we could not able to reach Public Networks from LAN through Secondary ASA upto 10 mins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need to change the global timeouts configured for connections and Xlate to process the timeout on liveconnections to reiniate the connections?&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2017 04:13:58 GMT</pubDate>
    <dc:creator>Chaitanya Krishna Narra</dc:creator>
    <dc:date>2017-09-06T04:13:58Z</dc:date>
    <item>
      <title>ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3179948#M1066454</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured failover (&lt;SPAN&gt;Active/Standby)&amp;nbsp;&lt;/SPAN&gt;between our 2 ASA firewalls using the configuration giving below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tested the failover by power down our Primary ASA (ASA-1) firewall and our Secondary ASA (ASA-2) is become Active. But, the secondary Firewall taking more time (up to 10 Mins) to forward the traffic on ISP's, after the Primary firewall is down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone please help me to reduce the time, to start forwarding the traffic from Secondary ASA to reach internet on ISP's, after the Primary firewall is down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Failover Configuration ASA - 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# failover&lt;BR /&gt;# failover lan unit primary&lt;BR /&gt;# failover lan interface folink GigabitEthernet1/8&lt;BR /&gt;# failover link statelink GigabitEthernet1/7&lt;BR /&gt;# failover interface ip folink 10.10.10.1 255.255.255.252 standby 10.10.10.2&lt;BR /&gt;# failover interface ip statelink 10.10.10.5 255.255.255.252 standby 10.10.10.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Failover configuration ASA - 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# failover&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# failover lan unit secondary&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# failover lan interface folink GigabitEthernet1/8&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# failover link statelink GigabitEthernet1/7&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# failover interface ip folink 10.10.10.1 255.255.255.252 standby 10.10.10.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# failover interface ip statelink 10.10.10.5 255.255.255.252 standby 10.10.10.6&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3179948#M1066454</guid>
      <dc:creator>Chaitanya Krishna Narra</dc:creator>
      <dc:date>2020-02-21T14:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3179962#M1066455</link>
      <description>&lt;P&gt;This is not normal behavior. The secondary unit should take over the active role within 15 seconds and start forwarding traffic. What did you see on the logs in that timespan? Did your traffic reach the ASA, was the ASA reachable from the internet?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 07:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3179962#M1066455</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-09-05T07:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180405#M1066457</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your responce to my query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We observe Secondary ASA has taken the "Active" role as soon as the Primary unit has failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can able to reach the Firewall from LAN and able to ping the public Networks from Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, we could not able to reach Public Networks from LAN through Secondary ASA upto 10 mins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need to change the global timeouts configured for connections and Xlate to process the timeout on liveconnections to reiniate the connections?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 04:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180405#M1066457</guid>
      <dc:creator>Chaitanya Krishna Narra</dc:creator>
      <dc:date>2017-09-06T04:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180432#M1066459</link>
      <description>&lt;P&gt;What protocol do use to to reach ISP from firewall. I am more interested in the topology&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 05:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180432#M1066459</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2017-09-06T05:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180455#M1066460</link>
      <description>&lt;P&gt;&lt;SPAN&gt;S&lt;/SPAN&gt;&lt;SPAN&gt;tatefull failover should&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;synchronize the connections to the standby unit so that this device can directly take over the forwarding. Does "show failover" show any signs&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;of malfunction?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have a maintenace window? Then do a "no failover active" on the active unit&amp;nbsp;to test if failover works when initiated gracefully.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 07:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180455#M1066460</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-09-06T07:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180465#M1066463</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we do "no failover active" on Primary Firewall, the Secondary Firewall is able to start forwarding the traffic within sec's.&lt;/P&gt;&lt;P&gt;But, if we powerdown the Primary Firewall (Active) without "no failover active" command, Secondary Firewall changing the role to "Active" and taking time to forward the traffic (upto 10 mins).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On status of "Show failover", we can see interface status of both Firewalls is on "Normal" and can able to see Active/Standby status on Primary/Secondary firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are routing the traffic on Firewall using "Static and Default" routes and please find the attached for network topology.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 07:32:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180465#M1066463</guid>
      <dc:creator>Chaitanya Krishna Narra</dc:creator>
      <dc:date>2017-09-06T07:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180473#M1066465</link>
      <description>&lt;P&gt;Your topology is quite common and normaly works as expected. Can you post the output of "show failover"?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 07:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180473#M1066465</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-09-06T07:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180539#M1066467</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the attached, for output of "show failover" from Primary and Secondary Firewalls.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 11:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180539#M1066467</guid>
      <dc:creator>Chaitanya Krishna Narra</dc:creator>
      <dc:date>2017-09-06T11:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180552#M1066469</link>
      <description>&lt;P&gt;Please don't use word-documents to post text, just use text-documents ...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the output I don't see anything that should cause these problems. I would upgrade the ASAs to lhe latest&amp;nbsp;interims-release and test again.&amp;nbsp;The release-notes don't mention this problem, but there are other failover related bugs fixed.&lt;/P&gt;
&lt;P&gt;If that all doesn't help&amp;nbsp;(and no other one has an idea) you should open a TAC-case.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 11:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180552#M1066469</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-09-06T11:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180914#M1066472</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your observations and suggestions on this issue.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 05:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-active-standby/m-p/3180914#M1066472</guid>
      <dc:creator>Chaitanya Krishna Narra</dc:creator>
      <dc:date>2017-09-07T05:53:54Z</dc:date>
    </item>
  </channel>
</rss>

