<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387515#M1080056</link>
    <description>&lt;P&gt;which kind of info.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Apr 2021 12:44:37 GMT</pubDate>
    <dc:creator>alex210</dc:creator>
    <dc:date>2021-04-15T12:44:37Z</dc:date>
    <item>
      <title>ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387441#M1080052</link>
      <description>&lt;P&gt;Hi folks ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had an issue when failover the ASA from the primary to secondary node. only one group fails to the secondary node.&lt;/P&gt;&lt;P&gt;below some outputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA# show failover state&lt;/P&gt;&lt;P&gt;State Last Failure Reason Date/Time&lt;/P&gt;&lt;P&gt;This host - Secondary&lt;BR /&gt;Group 1 Failed Ifc Failure 12:52:56 Apr 10 2021&lt;BR /&gt;admin temp: No Link&lt;BR /&gt;Group 2 Active None&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other host - Primary&lt;BR /&gt;Group 1 Active None&lt;/P&gt;&lt;P&gt;Group 2 Standby Ready None&lt;/P&gt;&lt;P&gt;====Configuration State===&lt;BR /&gt;Sync Done - STANDBY&lt;BR /&gt;====Communication State===&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 10:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387441#M1080052</guid>
      <dc:creator>alex210</dc:creator>
      <dc:date>2021-04-15T10:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387443#M1080053</link>
      <description>&lt;P&gt;If this Active / Active Multi context&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you getting error :&lt;STRONG&gt;&amp;nbsp; Group 1 Failed Ifc Failure 12:52:56 Apr 10 2021&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;below thread may help you.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/asa-context-failover-ifc-failure/m-p/4313898" target="_blank"&gt;https://community.cisco.com/t5/network-security/asa-context-failover-ifc-failure/m-p/4313898&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still have issue you need to post more information&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Version&lt;/P&gt;
&lt;P&gt;config&lt;/P&gt;
&lt;P&gt;fail over config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 10:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387443#M1080053</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-15T10:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387515#M1080056</link>
      <description>&lt;P&gt;which kind of info.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 12:44:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387515#M1080056</guid>
      <dc:creator>alex210</dc:creator>
      <dc:date>2021-04-15T12:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387549#M1080057</link>
      <description>&lt;P&gt;Version&lt;/P&gt;
&lt;P&gt;config&lt;/P&gt;
&lt;P&gt;fail over config&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 13:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4387549#M1080057</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-15T13:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388776#M1080097</link>
      <description>&lt;P&gt;ASA# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: FL-interface Port-channel2 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 35 of 1043 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.12(2), Mate 9.12(2)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This host: Primary&lt;BR /&gt;Group 1 State: Active&lt;BR /&gt;Active time: 69343 (sec)&lt;BR /&gt;Group 2 State: Active&lt;BR /&gt;Active time: 69238 (sec)&lt;/P&gt;&lt;P&gt;slot 0: FPR-2130 hw/sw rev (49.46/9.12(2)) status (Up Sys)&lt;BR /&gt;admin Interface out (20.40.20.161): Normal (Waiting)&lt;BR /&gt;admin Interface notused (0.0.0.0): Normal (Waiting)&lt;BR /&gt;admin Interface test_mgmt (192.168.1.1): Normal (Monitored)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Other host: Secondary&lt;BR /&gt;Group 1 State: Failed&lt;BR /&gt;Active time: 3 (sec)&lt;BR /&gt;Group 2 State: Standby Ready&lt;BR /&gt;Active time: 147 (sec)&lt;/P&gt;&lt;P&gt;slot 0: FPR-2130 hw/sw rev (49.46/9.12(2)) status (Up Sys)&lt;BR /&gt;admin Interface out (0.0.0.0): No Link (Waiting)&lt;BR /&gt;admin Interface no (0.0.0.0): Normal (Waiting)&lt;BR /&gt;admin Interface test_mgmt (192.168.1.2): Normal (Monitored)&lt;BR /&gt;&lt;BR /&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : state-interface Port-channel2.1 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 7655259088 0 9697939 65&lt;BR /&gt;sys cmd 7689514 0 7689511 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 7425396031 0 1768835 10&lt;BR /&gt;UDP conn 183195261 0 128711 0&lt;BR /&gt;ARP tbl 38950028 0 110605 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 14728 0 139 0&lt;BR /&gt;VPN IKEv1 P2 11476 0 135 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 434 0 0 0&lt;BR /&gt;SIP Tx 310 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 782 0 0 55&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 524 0 3 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;BR /&gt;Umbrella Device-ID 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 33 67722857&lt;BR /&gt;Xmit Q: 0 174 7801599118&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 12:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388776#M1080097</guid>
      <dc:creator>alex210</dc:creator>
      <dc:date>2021-04-17T12:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388913#M1080100</link>
      <description>&lt;P&gt;Still config is missing in this post as we requested, based on show failover here is my observation to check and fix :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;his host: Primary&lt;BR /&gt;Group 1 State: Active&lt;BR /&gt;Active time: 69343 (sec)&lt;BR /&gt;Group 2 State: Active&lt;BR /&gt;Active time: 69238 (sec)&lt;/P&gt;
&lt;P&gt;slot 0: FPR-2130 hw/sw rev (49.46/9.12(2)) status (Up Sys)&lt;BR /&gt;&lt;STRONG&gt;admin Interface out (20.40.20.161): Normal (Waiting)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;admin Interface notused (0.0.0.0): Normal (Waiting)&lt;/STRONG&gt;&lt;BR /&gt;admin Interface test_mgmt (192.168.1.1): Normal (Monitored)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Other host: Secondary&lt;BR /&gt;&lt;STRONG&gt;Group 1 State: Failed&lt;/STRONG&gt;&lt;BR /&gt;Active time: 3 (sec)&lt;BR /&gt;Group 2 State: Standby Ready&lt;BR /&gt;Active time: 147 (sec)&lt;/P&gt;
&lt;P&gt;slot 0: FPR-2130 hw/sw rev (49.46/9.12(2)) status (Up Sys)&lt;BR /&gt;&lt;STRONG&gt;admin Interface out (0.0.0.0): No Link (Waiting)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;admin Interface no (0.0.0.0): Normal (Waiting)&lt;/STRONG&gt;&lt;BR /&gt;admin Interface test_mgmt (192.168.1.2): Normal (Monitored)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some guide Lines :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://myitmicroblog.svbtle.com/asa-activeactive-failover-why-the-interface-status-is-unknownwaitingfailednotmonitored" target="_blank"&gt;https://myitmicroblog.svbtle.com/asa-activeactive-failover-why-the-interface-status-is-unknownwaitingfailednotmonitored&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 08:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388913#M1080100</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-18T08:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388937#M1080102</link>
      <description>&lt;P&gt;Most likely group 2 does not include the failed interface that caused group 1 to failover.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 09:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388937#M1080102</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-18T09:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388962#M1080103</link>
      <description>&lt;P&gt;I have an interface which is up on the active node and down on the standby node. can this caused the failover to fail ?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 11:16:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4388962#M1080103</guid>
      <dc:creator>alex210</dc:creator>
      <dc:date>2021-04-18T11:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4389000#M1080104</link>
      <description>&lt;P&gt;show us more information - related to config and what interface going down, we been asked this before, to get the right suggestion we need the right information,&amp;nbsp; we only guess the suggestions maybe not right to fix in time.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 13:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4389000#M1080104</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-18T13:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4389002#M1080105</link>
      <description>&lt;P&gt;which config do you want ? commands ..&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 13:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4389002#M1080105</guid>
      <dc:creator>alex210</dc:creator>
      <dc:date>2021-04-18T13:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4389005#M1080106</link>
      <description>&lt;P&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FL-interface Port-channel4&lt;BR /&gt;failover link state-interface Port-channel4.2&lt;BR /&gt;failover interface ip FL-interface 10.10.10.254 255.255.255.252 standby 10.10.10.253&lt;BR /&gt;failover interface ip state-interface 10.10.10.80 255.255.255.252 standby 10.10.10.81&lt;BR /&gt;failover group 1&lt;BR /&gt;preempt&lt;BR /&gt;failover group 2&lt;BR /&gt;secondary&lt;BR /&gt;preempt&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 14:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4389005#M1080106</guid>
      <dc:creator>alex210</dc:creator>
      <dc:date>2021-04-18T14:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4390701#M1080190</link>
      <description>&lt;P&gt;Hi Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if the community has had experiences or any discussion about the best practices to migrate two ASA firewalls in standalone mode operating in a critical network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The process is to migrate the two ASAs to new Firepower hardware with ASA image. in Multiple Context and Failover Active Active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each ASA old ASA will pass as a Context on the new hardware.&amp;nbsp;It is very interesting what I should do so I would like to know about the experiences in these cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other words,&amp;nbsp;Best practices for hardware migration from ASA Firewall to Firepower 2100 with active active failover ASA image and multiple contexts within a network in critical operation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance, Community&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 11:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4390701#M1080190</guid>
      <dc:creator>Hannibal</dc:creator>
      <dc:date>2021-04-21T11:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4390708#M1080191</link>
      <description>&lt;P&gt;i woluld suggest to open a new thread, this thread have different issue.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 11:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4390708#M1080191</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-21T11:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/4391309#M1080218</link>
      <description>&lt;P&gt;Thanks Balaji. I did that yesterday, I hope any comments. I had been looking into the community and no similar case&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 07:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/4391309#M1080218</guid>
      <dc:creator>Hannibal</dc:creator>
      <dc:date>2021-04-22T07:39:42Z</dc:date>
    </item>
  </channel>
</rss>

