<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall HA issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4097647#M1070758</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a strange issue that'why I hope someone here will give me a solution, at least a good lead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a new customer that called me because he had his VPN KO : anyconnect profile didn't work.&lt;/P&gt;&lt;P&gt;I saw that there was a HA configuration, and a failover occured because the active reloaded. The customer confirmed me there was an electrical issue.&lt;/P&gt;&lt;P&gt;The customer uploaded via ASDM the profile and it worked again, but there is this point : why the profile didn't exist on the standby unit ?&lt;/P&gt;&lt;P&gt;I saw in the failover that 3 interfaces (inside,outside &amp;amp; management) were monitored and 2 of them (management + inside) are in waiting state. For me, while those interfaces aren't monitored, the sync will fail (am I right for this point ?)&lt;/P&gt;&lt;P&gt;Then I search how those interfaces are linked between the two nodes.&lt;/P&gt;&lt;P&gt;I have :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;managementPrimary =&amp;gt; SwitchA =&amp;gt; SwitchB =&amp;gt; SwitchC =&amp;gt; managementSecondary (waiting state)&lt;/LI&gt;&lt;LI&gt;insidePrimary =&amp;gt; SwitchA =&amp;gt; SwitchB =&amp;gt; SwitchC =&amp;gt; insideSecondary (waiting state)&lt;/LI&gt;&lt;LI&gt;outsidePrimary =&amp;gt; SwitchD =&amp;gt; outsideSecondary&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Each interface is in access vlan.&lt;/P&gt;&lt;P&gt;I check that each vlan is created in Switch 1,B&amp;amp;C and those vlans are Ok in link between switches : for me there is no L2 issues on switches A,B&amp;amp;C&lt;/P&gt;&lt;P&gt;From a remote workstation, I am able to ping Primary and Secondary IP addresses for management and inside interfaces : for me there is no L3 issue for those interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is were I need some help : what could be the origin of this issue ? (the customer didn't know interfaces were in waiting state, I cannot tell if they were once monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Irwin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2020 14:39:44 GMT</pubDate>
    <dc:creator>i.leridant</dc:creator>
    <dc:date>2020-06-04T14:39:44Z</dc:date>
    <item>
      <title>Firewall HA issue</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4097647#M1070758</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a strange issue that'why I hope someone here will give me a solution, at least a good lead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a new customer that called me because he had his VPN KO : anyconnect profile didn't work.&lt;/P&gt;&lt;P&gt;I saw that there was a HA configuration, and a failover occured because the active reloaded. The customer confirmed me there was an electrical issue.&lt;/P&gt;&lt;P&gt;The customer uploaded via ASDM the profile and it worked again, but there is this point : why the profile didn't exist on the standby unit ?&lt;/P&gt;&lt;P&gt;I saw in the failover that 3 interfaces (inside,outside &amp;amp; management) were monitored and 2 of them (management + inside) are in waiting state. For me, while those interfaces aren't monitored, the sync will fail (am I right for this point ?)&lt;/P&gt;&lt;P&gt;Then I search how those interfaces are linked between the two nodes.&lt;/P&gt;&lt;P&gt;I have :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;managementPrimary =&amp;gt; SwitchA =&amp;gt; SwitchB =&amp;gt; SwitchC =&amp;gt; managementSecondary (waiting state)&lt;/LI&gt;&lt;LI&gt;insidePrimary =&amp;gt; SwitchA =&amp;gt; SwitchB =&amp;gt; SwitchC =&amp;gt; insideSecondary (waiting state)&lt;/LI&gt;&lt;LI&gt;outsidePrimary =&amp;gt; SwitchD =&amp;gt; outsideSecondary&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Each interface is in access vlan.&lt;/P&gt;&lt;P&gt;I check that each vlan is created in Switch 1,B&amp;amp;C and those vlans are Ok in link between switches : for me there is no L2 issues on switches A,B&amp;amp;C&lt;/P&gt;&lt;P&gt;From a remote workstation, I am able to ping Primary and Secondary IP addresses for management and inside interfaces : for me there is no L3 issue for those interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is were I need some help : what could be the origin of this issue ? (the customer didn't know interfaces were in waiting state, I cannot tell if they were once monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Irwin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 14:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4097647#M1070758</guid>
      <dc:creator>i.leridant</dc:creator>
      <dc:date>2020-06-04T14:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall HA issue</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4098009#M1070784</link>
      <description>&lt;P&gt;When you create (or modify) a VPN profile it doesn't automatically sync between the Active and Standby unit in an HA configuration. You need to manually copy the file across - just as you do with new ASA, ASDM or AnyConnect images.&lt;/P&gt;
&lt;P&gt;If you neglect to do so, a failover will result in the behavior your customer observed.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 03:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4098009#M1070784</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-06-05T03:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall HA issue</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4098089#M1070787</link>
      <description>&lt;P&gt;Thank you Marvin for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when I do a manual failover (the Primary is back in Active role) I see the same issue, and the behaviour seen by the customer is : "Failed to get configuration from secure gateway. Contact your system administrator"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Moreover, I have this message when I go in configure terminal :&lt;/P&gt;&lt;P&gt;"**** WARNING ****&lt;BR /&gt;Configuration Replication is NOT performed from Standby unit to Active unit&lt;BR /&gt;Configurations are no longer synchronized"&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 08:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4098089#M1070787</guid>
      <dc:creator>i.leridant</dc:creator>
      <dc:date>2020-06-05T08:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall HA issue</title>
      <link>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4098195#M1070798</link>
      <description>&lt;P&gt;You should never enter configure mode on a unit in standby role.&lt;/P&gt;
&lt;P&gt;Just make sure the anyconnect profile (xml file) specified in the webvpn config is present on both units, active and standby.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 12:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-ha-issue/m-p/4098195#M1070798</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-06-05T12:32:42Z</dc:date>
    </item>
  </channel>
</rss>

