<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active standby  failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4093570#M1070530</link>
    <description>&lt;P&gt;The reason is due to no link on monitored interface DMZ2:&lt;/P&gt;
&lt;PRE&gt;Interface DMZ2 (172.16.6.2): No Link (Waiting)&lt;/PRE&gt;</description>
    <pubDate>Thu, 28 May 2020 12:34:30 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-05-28T12:34:30Z</dc:date>
    <item>
      <title>Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4080345#M1069905</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have asa deployed active standby .&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my standby I don't have connectivity to DMZ&amp;nbsp; interface due to lack of budget .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the problem is , it shows active standby failure . Is it due to the&amp;nbsp; missing connectivity&lt;/P&gt;&lt;P&gt;or something else&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 09:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4080345#M1069905</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2020-05-06T09:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4080406#M1069910</link>
      <description>&lt;P&gt;The command "show failover" will tell you the reason the Standby unit is marked failed.&lt;/P&gt;
&lt;P&gt;If it is only because of an interface you expect to not come up then you can remove that interface from failover monitoring and it will not affect the failover pair state.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 11:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4080406#M1069910</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-06T11:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4081302#M1069953</link>
      <description>&lt;P&gt;But with not active DMZ interface on the Secondary, any hosts in the DMZ will not be accessible. The Secondary needs layer 1 and layer 2 connection to the DMZ vlan/switch to function correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 14:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4081302#M1069953</guid>
      <dc:creator>Michael ONeil</dc:creator>
      <dc:date>2020-05-07T14:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4081483#M1069969</link>
      <description>&lt;P&gt;just to add what other said. you can give a command &lt;STRONG&gt;show failover history&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the reason you cant the see DMZ could be layer 2 (vlan) issue. &lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 19:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4081483#M1069969</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-05-07T19:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4093465#M1070523</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;here is the failover result . but i dont kmow the reason . Please help&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: FW-Failover GigabitEthernet0/6 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 4 of 1025 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;failover replication http&lt;BR /&gt;Version: Ours 9.2(4)27, Mate 9.2(4)27&lt;BR /&gt;Last Failover at: 15:07:53 MSK May 3 2020&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 10787760 (sec)&lt;BR /&gt;slot 0: ASA5585-SSP-20 hw/sw rev (3.0/9.2(4)27) status (Up Sys)&lt;BR /&gt;Interface Outside (OUTSIDE-IP): Normal (Waiting)&lt;BR /&gt;Interface DMZ1 (172.16.5.1): Normal (Waiting)&lt;BR /&gt;Interface Inside (172.16.3.1): Normal (Waiting)&lt;BR /&gt;Interface DMZ2 (172.16.6.1): Normal (Waiting)&lt;BR /&gt;slot 1: ASA5585-NM-4-10GE hw/sw rev (1.0/) status (Up)&lt;BR /&gt;slot 2: empty&lt;BR /&gt;Other host: Secondary - Failed&lt;BR /&gt;Active time: 897 (sec)&lt;BR /&gt;slot 0: ASA5585-SSP-20 hw/sw rev (3.0/9.2(4)27) status (Up Sys)&lt;BR /&gt;Interface Outside (0.0.0.0): Normal (Waiting)&lt;BR /&gt;Interface DMZ1 (172.16.5.2): Normal (Waiting)&lt;BR /&gt;Interface Inside (172.16.3.2): Normal (Waiting)&lt;BR /&gt;Interface DMZ2 (172.16.6.2): No Link (Waiting)&lt;BR /&gt;slot 1: ASA5585-NM-4-10GE hw/sw rev (1.0/) status (Up)&lt;BR /&gt;slot 2: empty&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : FW-Failover GigabitEthernet0/6 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 2688694275 0 2828542 0&lt;BR /&gt;sys cmd 2539556 0 2539554 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 1825689955 0 194589 0&lt;BR /&gt;UDP conn 809062791 0 88688 0&lt;BR /&gt;ARP tbl 48431735 0 5646 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 1135 0 4 0&lt;BR /&gt;VPN IKEv1 P2 15367 0 7 0&lt;BR /&gt;VPN IKEv2 SA 126290 0 0 0&lt;BR /&gt;VPN IKEv2 P2 4645 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 2801048 0 11 0&lt;BR /&gt;Route Session 3001 0 28 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 18752 0 15 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 23 2830358&lt;BR /&gt;Xmit Q: 0 120 2713687577&lt;BR /&gt;FW#&lt;BR /&gt;FW# write&lt;BR /&gt;Building configuration...&lt;BR /&gt;Cryptochecksum: 5d2ea11b 29524c5e 8d5845c9 6258bb36&lt;/P&gt;&lt;P&gt;126887 bytes copied in 1.260 secs (126887 bytes/sec)&lt;BR /&gt;[OK]&lt;BR /&gt;FW# sh fa&lt;BR /&gt;FW# sh failover h&lt;BR /&gt;FW# sh failover history&lt;BR /&gt;==========================================================================&lt;BR /&gt;From State To State Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;08:05:43 MSK Jan 7 2020&lt;BR /&gt;Failed Standby Ready Interface check&lt;/P&gt;&lt;P&gt;08:05:54 MSK Jan 7 2020&lt;BR /&gt;Standby Ready Just Active Other unit wants me Active&lt;/P&gt;&lt;P&gt;08:05:54 MSK Jan 7 2020&lt;BR /&gt;Just Active Active Drain Other unit wants me Active&lt;/P&gt;&lt;P&gt;08:05:54 MSK Jan 7 2020&lt;BR /&gt;Active Drain Active Applying Config Other unit wants me Active&lt;/P&gt;&lt;P&gt;08:05:54 MSK Jan 7 2020&lt;BR /&gt;Active Applying Config Active Config Applied Other unit wants me Active&lt;/P&gt;&lt;P&gt;08:05:54 MSK Jan 7 2020&lt;BR /&gt;Active Config Applied Active Other unit wants me Active&lt;/P&gt;&lt;P&gt;14:51:20 MSK May 3 2020&lt;BR /&gt;Active Failed Interface check&lt;/P&gt;&lt;P&gt;14:51:30 MSK May 3 2020&lt;BR /&gt;Failed Standby Ready Interface check&lt;/P&gt;&lt;P&gt;14:51:38 MSK May 3 2020&lt;BR /&gt;Standby Ready Just Active Other unit wants me Active&lt;/P&gt;&lt;P&gt;14:51:38 MSK May 3 2020&lt;BR /&gt;Just Active Active Drain Other unit wants me Active&lt;/P&gt;&lt;P&gt;14:51:38 MSK May 3 2020&lt;BR /&gt;Active Drain Active Applying Config Other unit wants me Active&lt;/P&gt;&lt;P&gt;14:51:38 MSK May 3 2020&lt;BR /&gt;Active Applying Config Active Config Applied Other unit wants me Active&lt;/P&gt;&lt;P&gt;14:51:38 MSK May 3 2020&lt;BR /&gt;Active Config Applied Active Other unit wants me Active&lt;/P&gt;&lt;P&gt;14:52:55 MSK May 3 2020&lt;BR /&gt;Active Failed Interface check&lt;/P&gt;&lt;P&gt;15:07:45 MSK May 3 2020&lt;BR /&gt;Failed Standby Ready Interface check&lt;/P&gt;&lt;P&gt;15:07:53 MSK May 3 2020&lt;BR /&gt;Standby Ready Just Active Other unit wants me Active&lt;/P&gt;&lt;P&gt;15:07:53 MSK May 3 2020&lt;BR /&gt;Just Active Active Drain Other unit wants me Active&lt;/P&gt;&lt;P&gt;15:07:53 MSK May 3 2020&lt;BR /&gt;Active Drain Active Applying Config Other unit wants me Active&lt;/P&gt;&lt;P&gt;15:07:53 MSK May 3 2020&lt;BR /&gt;Active Applying Config Active Config Applied Other unit wants me Active&lt;/P&gt;&lt;P&gt;15:07:53 MSK May 3 2020&lt;BR /&gt;Active Config Applied Active Other unit wants me Active&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 10:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4093465#M1070523</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2020-05-28T10:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4093570#M1070530</link>
      <description>&lt;P&gt;The reason is due to no link on monitored interface DMZ2:&lt;/P&gt;
&lt;PRE&gt;Interface DMZ2 (172.16.6.2): No Link (Waiting)&lt;/PRE&gt;</description>
      <pubDate>Thu, 28 May 2020 12:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4093570#M1070530</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-28T12:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4099679#M1070878</link>
      <description>Hi,&lt;BR /&gt;If I just add a switch (there is no uplink for the switch ) and connect the interface to the switch , does it will work ?&lt;BR /&gt;Thanks</description>
      <pubDate>Mon, 08 Jun 2020 22:41:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4099679#M1070878</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2020-06-08T22:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4099736#M1070883</link>
      <description>&lt;P&gt;Yes that would work.&lt;/P&gt;
&lt;P&gt;Or you could just exclude the DMZ interface from failover monitoring.&lt;/P&gt;
&lt;P&gt;One line config change vs install new hardware - whichever you prefer.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 02:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4099736#M1070883</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-06-09T02:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113841#M1071736</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried to install new hardware ,but after couple of minutes asa complaining no link&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be the reason&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 10:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113841#M1071736</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2020-07-06T10:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113847#M1071737</link>
      <description>&lt;P&gt;You're not giving enough information to give you a useful reply.&lt;/P&gt;
&lt;P&gt;Are both ASAs connected to the new hardware? Are their DMZ interfaces both up and in the same VLAN? Have you configured a standby address for the DMZ interface?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 10:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113847#M1071737</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-06T10:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113865#M1071739</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Below is the topology diagram . Secondary&amp;nbsp; asa I don't have connectivity to the DMZ switch&amp;nbsp; since it is&amp;nbsp; geographically far from the dmz switch . .&lt;/P&gt;&lt;P&gt;(there are multiple dmz zone&amp;nbsp; but in the diagram I Showed only one . other dmz has identical configuration for both location )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I thought of putting a dummy l2 switch in the secondary location .&lt;/P&gt;&lt;P&gt;ASa standby&amp;nbsp; ip address configured on standby ASA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this information is enough&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled Diagram (4).jpg" style="width: 581px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78391i28BB1B0EEA21C312/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled Diagram (4).jpg" alt="Untitled Diagram (4).jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 11:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113865#M1071739</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2020-07-06T11:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Active standby  failure</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113888#M1071742</link>
      <description>&lt;P&gt;If the Active ASA cannot reach the configured standby address for the DMZ on the Standby ASA, failover monitoring will show the Standby unit has failed (assuming default monitoring config).&lt;/P&gt;
&lt;P&gt;Why do you want to monitor that interface if there's nothing "real" connected to it? Any result you get will be misleading at best.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 11:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-failure/m-p/4113888#M1071742</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-06T11:44:19Z</dc:date>
    </item>
  </channel>
</rss>

