<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA interface monitoring in waiting state with RPF enabled in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4137933#M1073114</link>
    <description>&lt;P&gt;Just to give you an update: We didn't test removal of OSPF-filter but urged customer to upgrade and test again. SW is from 2015, we assume a bug.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2020 08:45:22 GMT</pubDate>
    <dc:creator>klaus.kruse</dc:creator>
    <dc:date>2020-08-19T08:45:22Z</dc:date>
    <item>
      <title>ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123415#M1072212</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've a pair of ASA5585 running some dated version&amp;nbsp;9.2(3)4 . It's a failover cluster and we use interface monitoring. I wondered that on secondary one monitored interface was in state "Normal (Waiting)". I did an ICMP packet trace and found this result:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: VPN&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (rpf-violated) Reverse-path verify failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After deactivating RPF, status went to "Normal (Monitored)". Then I activated RPF again and status keeps like this. Looks like a bug for me, but I haven't found the right one in bugsearch. Can anyone help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Klaus Kruse&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 09:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123415#M1072212</guid>
      <dc:creator>klaus.kruse</dc:creator>
      <dc:date>2020-07-22T09:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123465#M1072214</link>
      <description>&lt;P&gt;Could you do a show running-config for the VPN interface and make sure that there is a standby IP configured for that interface?&amp;nbsp; Usually when the interface is in Normal(Waiting) state it means that a standby IP has not yet been configured on that interface.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 11:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123465#M1072214</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-22T11:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123474#M1072217</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your suggestion, but standby IP is configured correctly:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Port-channel1.100&lt;BR /&gt;description VPN&lt;BR /&gt;vlan 100&lt;BR /&gt;nameif VPN&lt;BR /&gt;security-level 60&lt;BR /&gt;ip address 10.127.255.9 255.255.255.248 standby 10.127.255.10&lt;BR /&gt;ospf database-filter all out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have this console log for reference:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA/act/pri# ping 10.127.255.10&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.127.255.10, timeout is 2 seconds:&lt;BR /&gt;?????&lt;/P&gt;&lt;P&gt;ASA/act/pri# conf t&lt;/P&gt;&lt;P&gt;ASA/act/pri(config)# no ip verify reverse-path interface VPN&lt;/P&gt;&lt;P&gt;ASA/act/pri(config)# exit&lt;/P&gt;&lt;P&gt;ASA/act/pri# ping 10.127.255.10&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.127.255.10, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 11:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123474#M1072217</guid>
      <dc:creator>klaus.kruse</dc:creator>
      <dc:date>2020-07-22T11:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123488#M1072220</link>
      <description>&lt;P&gt;Interesting.&lt;/P&gt;
&lt;P&gt;Would it be possible to remove the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;ospf database-filter all out&lt;/STRONG&gt; command from the interface for a test?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 12:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123488#M1072220</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-22T12:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123514#M1072222</link>
      <description>I can try that, will let you know the outcome.</description>
      <pubDate>Wed, 22 Jul 2020 12:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4123514#M1072222</guid>
      <dc:creator>klaus.kruse</dc:creator>
      <dc:date>2020-07-22T12:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4137933#M1073114</link>
      <description>&lt;P&gt;Just to give you an update: We didn't test removal of OSPF-filter but urged customer to upgrade and test again. SW is from 2015, we assume a bug.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 08:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4137933#M1073114</guid>
      <dc:creator>klaus.kruse</dc:creator>
      <dc:date>2020-08-19T08:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA interface monitoring in waiting state with RPF enabled</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4137946#M1073115</link>
      <description>&lt;P&gt;Is there any reason you are not using a /30?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you could, change it to a /30 and test again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I bet if you look at the arp table on that interface, you will notice the counter/timer will reset over and over again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 09:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-monitoring-in-waiting-state-with-rpf-enabled/m-p/4137946#M1073115</guid>
      <dc:creator>Heino Human</dc:creator>
      <dc:date>2020-08-19T09:07:28Z</dc:date>
    </item>
  </channel>
</rss>

