<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA multi context failover link down issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110535#M1071516</link>
    <description>&lt;P&gt;Dear experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having 2 physical cisco ASA firewalls and both are in multi context mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem i am facing is, Fail over is fail. I found out that on standby ASA, the link is showing down. I changed the cable but still the issue is there. Please find the show commands below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA01/act(config)# show fail&lt;BR /&gt;Failover On&lt;BR /&gt;Last Failover at: 17:09:43 GMT Jun 15 2020&lt;BR /&gt;This context: Active&lt;BR /&gt;Active time: 1139504 (sec)&lt;BR /&gt;Interface internet (192.168.88.4): Normal (Waiting)&lt;BR /&gt;Interface outside (192.168.89.4): Normal (Waiting)&lt;BR /&gt;Interface DMZ (192.168.110.1): Normal (Not-Monitored)&lt;BR /&gt;Interface test (192.168.211.1): Normal (Waiting)&lt;BR /&gt;Interface DMZ-Citrix-GW (192.168.250.1): Normal (Not-Monitored)&lt;BR /&gt;Interface old-network (192.168.253.1): Normal (Waiting)&lt;BR /&gt;Interface inside (192.168.87.4): Normal (Monitored)&lt;BR /&gt;Peer context: Failed&lt;BR /&gt;Active time: 64 (sec)&lt;BR /&gt;Interface internet (192.168.88.5): No Link (Waiting)&lt;BR /&gt;Interface outside (192.168.89.5): No Link (Waiting)&lt;BR /&gt;Interface DMZ (192.168.110.2): Normal (Not-Monitored)&lt;BR /&gt;Interface test (192.168.211.2): No Link (Waiting)&lt;BR /&gt;Interface DMZ-Citrix-GW (192.168.250.2): Normal (Not-Monitored)&lt;BR /&gt;Interface old-network (192.168.253.2): No Link (Waiting)&lt;BR /&gt;Interface inside (192.168.87.5): Normal (Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-ASA01/stby# sh int ip br&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.88 192.168.88.5 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.89 192.168.89.5 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.110 192.168.110.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.211 192.168.211.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.250 192.168.250.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.253 192.168.253.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/5 192.168.87.5 YES CONFIG up up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch is learning is MAC address of this ASA but still i cannot make it up.&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jun 2020 17:48:00 GMT</pubDate>
    <dc:creator>pro6151945</dc:creator>
    <dc:date>2020-06-28T17:48:00Z</dc:date>
    <item>
      <title>ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110535#M1071516</link>
      <description>&lt;P&gt;Dear experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having 2 physical cisco ASA firewalls and both are in multi context mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem i am facing is, Fail over is fail. I found out that on standby ASA, the link is showing down. I changed the cable but still the issue is there. Please find the show commands below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA01/act(config)# show fail&lt;BR /&gt;Failover On&lt;BR /&gt;Last Failover at: 17:09:43 GMT Jun 15 2020&lt;BR /&gt;This context: Active&lt;BR /&gt;Active time: 1139504 (sec)&lt;BR /&gt;Interface internet (192.168.88.4): Normal (Waiting)&lt;BR /&gt;Interface outside (192.168.89.4): Normal (Waiting)&lt;BR /&gt;Interface DMZ (192.168.110.1): Normal (Not-Monitored)&lt;BR /&gt;Interface test (192.168.211.1): Normal (Waiting)&lt;BR /&gt;Interface DMZ-Citrix-GW (192.168.250.1): Normal (Not-Monitored)&lt;BR /&gt;Interface old-network (192.168.253.1): Normal (Waiting)&lt;BR /&gt;Interface inside (192.168.87.4): Normal (Monitored)&lt;BR /&gt;Peer context: Failed&lt;BR /&gt;Active time: 64 (sec)&lt;BR /&gt;Interface internet (192.168.88.5): No Link (Waiting)&lt;BR /&gt;Interface outside (192.168.89.5): No Link (Waiting)&lt;BR /&gt;Interface DMZ (192.168.110.2): Normal (Not-Monitored)&lt;BR /&gt;Interface test (192.168.211.2): No Link (Waiting)&lt;BR /&gt;Interface DMZ-Citrix-GW (192.168.250.2): Normal (Not-Monitored)&lt;BR /&gt;Interface old-network (192.168.253.2): No Link (Waiting)&lt;BR /&gt;Interface inside (192.168.87.5): Normal (Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-ASA01/stby# sh int ip br&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.88 192.168.88.5 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.89 192.168.89.5 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.110 192.168.110.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.211 192.168.211.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.250 192.168.250.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.253 192.168.253.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/5 192.168.87.5 YES CONFIG up up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch is learning is MAC address of this ASA but still i cannot make it up.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2020 17:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110535#M1071516</guid>
      <dc:creator>pro6151945</dc:creator>
      <dc:date>2020-06-28T17:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110543#M1071517</link>
      <description>&lt;P&gt;How are they connected in the network, do you have any topology.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as per the log port, 4 looks down, investigate physically and also check switch side any logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2020 18:25:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110543#M1071517</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-06-28T18:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110699#M1071527</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are connected to WSW01 Switch. Please see below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WSW01#sh int status | i ASA&lt;BR /&gt;Gi1/0/2 To--SH-ASA01- connected trunk a-full a-1000 10/100/1000BaseTX&lt;BR /&gt;Gi1/0/3 To--SH-ASA01- connected trunk a-full a-1000 10/100/1000BaseTX&lt;BR /&gt;Gi1/0/4 To--SH-ASA01- connected trunk a-full a-1000 10/100/1000BaseTX&lt;BR /&gt;Gi2/0/2 To--SH-ASA02- connected trunk a-full a-1000 10/100/1000BaseTX&lt;BR /&gt;Gi2/0/3 To--SH-ASA02- connected trunk a-full a-1000 10/100/1000BaseTX&lt;BR /&gt;Gi2/0/4 To--SH-ASA02- connected trunk a-full a-1000 10/100/1000BaseTX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WSW01#sh mac address-table interface Gi2/0/4 &lt;STRONG&gt;(this port on ASA side is showing down)&lt;/STRONG&gt;&lt;BR /&gt;Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;/P&gt;&lt;P&gt;Vlan Mac Address Type Ports&lt;BR /&gt;---- ----------- -------- -----&lt;BR /&gt;88 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;253 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;211 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;89 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;110 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;250 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;Total Mac Addresses for this criterion: 6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on ASA-01&lt;/P&gt;&lt;P&gt;-ASA01/act(config)# sh int ip br&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/4.88 192.168.88.4 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4.89 192.168.89.4 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4.110 192.168.110.1 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4.211 192.168.211.1 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4.250 192.168.250.1 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4.253 192.168.253.1 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/5 192.168.87.4 YES CONFIG up up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on ASA-2 (which is standby)&lt;/P&gt;&lt;P&gt;ASA01/stby(config)# sh int ip br&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.88 192.168.88.5 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.89 192.168.89.5 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.110 192.168.110.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.211 192.168.211.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.250 192.168.250.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4.253 192.168.253.2 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/5 192.168.87.5 YES CONFIG up up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked the cable and it looks fine and switch is learning the MAC address as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 08:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110699#M1071527</guid>
      <dc:creator>pro6151945</dc:creator>
      <dc:date>2020-06-29T08:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110934#M1071548</link>
      <description>&lt;P&gt;There may be small information we missing here. Can you post ASA side config(striping all security info) - also Switch side config, please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 17:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110934#M1071548</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-06-29T17:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110959#M1071554</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please define exactly which section you want me to share because the config is huge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 18:47:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110959#M1071554</guid>
      <dc:creator>pro6151945</dc:creator>
      <dc:date>2020-06-29T18:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110960#M1071555</link>
      <description>&lt;P&gt;I am more looking at interface config both the side. if possible show cdp neigh.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 18:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4110960#M1071555</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-06-29T18:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA multi context failover link down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4111684#M1071589</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Switch connected to ASA&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WSW01#sh ip int br | i 2/0/4&lt;BR /&gt;&lt;STRONG&gt;GigabitEthernet2/0/4 unassigned YES unset up up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2/0/4&lt;BR /&gt;description To-ASA02-G0/4&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;WSW01#sh cdp nei int&lt;BR /&gt;WSW01#sh cdp nei internalInterface gi&lt;BR /&gt;WSW01#sh cdp nei internalInterface ?&lt;BR /&gt;&amp;lt;0-9&amp;gt; InternalInterface interface number&lt;/P&gt;&lt;P&gt;WSW01#sh mac add&lt;BR /&gt;&lt;BR /&gt;WSW01#sh mac address-table interface gigabitEthernet 2/0/4&lt;BR /&gt;Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;/P&gt;&lt;P&gt;Vlan Mac Address Type Ports&lt;BR /&gt;---- ----------- -------- -----&lt;BR /&gt;88 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;253 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;211 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;89 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;110 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;250 0062.ecd1.88f3 DYNAMIC Gi2/0/4&lt;BR /&gt;Total Mac Addresses for this criterion: 6&lt;BR /&gt;WSW01#&lt;BR /&gt;WSW01#sh int status | i Gi2/0/4&lt;BR /&gt;Gi2/0/4 To--ASA02- connected trunk a-full a-1000 10/100/1000BaseTX&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA01/stby(config)# sh int GigabitEthernet0/4&lt;BR /&gt;Interface GigabitEthernet0/4 "", is &lt;STRONG&gt;down&lt;/STRONG&gt;, line protocol is &lt;STRONG&gt;down&lt;/STRONG&gt;&lt;BR /&gt;Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex, Auto-Speed&lt;BR /&gt;Input flow control is unsupported, output flow control is off&lt;BR /&gt;Available for allocation to a context&lt;BR /&gt;MAC address &lt;STRONG&gt;0062.ecd1.88f3&lt;/STRONG&gt;, MTU not set&lt;BR /&gt;IP address unassigned&lt;BR /&gt;0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (511/511)&lt;BR /&gt;output queue (blocks free curr/low): hardware (511/511)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-ASA01/stby(config)# sh int ip br | i GigabitEthernet0/4&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.88 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.89 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.110 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.211 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.250 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/4.253 unassigned YES unset down down&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/4&lt;BR /&gt;interface GigabitEthernet0/4.88&lt;BR /&gt;vlan 88&lt;BR /&gt;interface GigabitEthernet0/4.89&lt;BR /&gt;vlan 89&lt;BR /&gt;interface GigabitEthernet0/4.110&lt;BR /&gt;description *** DMZ FE ***&lt;BR /&gt;vlan 110&lt;BR /&gt;interface GigabitEthernet0/4.211&lt;BR /&gt;vlan 211&lt;BR /&gt;interface GigabitEthernet0/4.250&lt;BR /&gt;vlan 250&lt;BR /&gt;interface GigabitEthernet0/4.253&lt;BR /&gt;vlan 253&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Above are config between the switch and the ASA, you can see that switch is learning the mac for the ASA and status is up on switch side. CDP it is not learning because other side is ASA and due to policies its not showing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please assist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 06:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-failover-link-down-issue/m-p/4111684#M1071589</guid>
      <dc:creator>pro6151945</dc:creator>
      <dc:date>2020-07-01T06:36:19Z</dc:date>
    </item>
  </channel>
</rss>

