<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD HA Packet-Tracer Output in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166452#M1074733</link>
    <description>&lt;P&gt;Could you issue show failover on the standby (active) unit just to verify the failover status.&amp;nbsp; Also, Could you check the connected switch ARP table to verify that the standby FTD MAC address has been associated with the Active unit IP.&lt;/P&gt;
&lt;P&gt;Also, you say that the bug you posted applies to different devices, which devices do you have installed?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2020 09:10:44 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-10-14T09:10:44Z</dc:date>
    <item>
      <title>FTD HA Packet-Tracer Output</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166328#M1074727</link>
      <description>&lt;P&gt;Working on a pair of 2130s running 6.2.3.12 and setup in HA.&amp;nbsp; Having some issues with traffic passing from 1 interface to another even though the policies look correct.&amp;nbsp; At present the secondary unit is the Active unit in the pair.&amp;nbsp; If i go into advanced troubleshooting on the secondary (Active) unit and go through packet-tracer I get this result:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: Inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Device_Management&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (fo-standby) Dropped by standby unit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However if I run through the same packet-tracer on the primary (now Standby unit) I get this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: Inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Device_Management&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll have access to some equipment tomorrow to actually get a packet capture for review but was curious as to why I'm seeing the results I am in packet-tracer.&amp;nbsp; I saw a bug (&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf72068/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf72068/?rfs=iqvred&lt;/A&gt;) but that applies to different devices and these units aren't in transparent mode.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 06:03:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166328#M1074727</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-10-14T06:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Packet-Tracer Output</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166408#M1074730</link>
      <description>&lt;P&gt;Never came across this before, but it looks like a bug to me. Based on my experience, the FTD 6.2.3.x is not stable and has a bunch of bugs. I would raise a TAC if upgrading it is not an option.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 08:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166408#M1074730</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-14T08:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Packet-Tracer Output</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166452#M1074733</link>
      <description>&lt;P&gt;Could you issue show failover on the standby (active) unit just to verify the failover status.&amp;nbsp; Also, Could you check the connected switch ARP table to verify that the standby FTD MAC address has been associated with the Active unit IP.&lt;/P&gt;
&lt;P&gt;Also, you say that the bug you posted applies to different devices, which devices do you have installed?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 09:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166452#M1074733</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-10-14T09:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Packet-Tracer Output</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166670#M1074746</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp; Going directly to the FTDs the Primary unit was in fact the Active and the FMC was wrong.&amp;nbsp; Forcing the re-sync corrected the status.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 13:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-packet-tracer-output/m-p/4166670#M1074746</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-10-14T13:10:55Z</dc:date>
    </item>
  </channel>
</rss>

