<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5525 - Failover troubleshooting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546925#M1087135</link>
    <description>&lt;P&gt;To check how many licences you have for your anyconnect. Give command "show version" in it there will be the information how many anyconnect licences you have purchased.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to check how many user are connected to anyconnect give command "show vpn-session detail anyconnect" or "show vpn-session summary"&lt;/P&gt;</description>
    <pubDate>Mon, 07 Feb 2022 21:31:31 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2022-02-07T21:31:31Z</dc:date>
    <item>
      <title>ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546058#M1087086</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I m new to ASA 5525, I just run Show Failover command, it shows secondary in use how dow i troubleshoot the issue to bring back the Primary one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;KALEEM&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 09:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546058#M1087086</guid>
      <dc:creator>kaleemullahbilal1</dc:creator>
      <dc:date>2022-02-05T09:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546062#M1087087</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/77080"&gt;@kaleemullahbilal1&lt;/a&gt; if the original active device rebooted the secondary would take over and remain active until it is rebooted or if the other device is manually specified as active again.&lt;/P&gt;
&lt;P&gt;Is there an issue with the original failover primary device? Provide the output of "show failover".&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 10:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546062#M1087087</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-02-05T10:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546064#M1087088</link>
      <description>&lt;P&gt;Dear Rob,&lt;/P&gt;&lt;P&gt;Here is the output. usually when i run this command it shows as primary, Primary still up and i can ping ..what is the best practice shoud i make Primary active manualy ? need to know the reson of that switch ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NSH-ASA/sec/act# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: FAILOVER GigabitEthernet0/7 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 3 of 216 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;failover replication http&lt;BR /&gt;Version: Ours 9.8(1), Mate 9.8(1)&lt;BR /&gt;Serial Number: Ours FCH2141JDF5, Mate FCH2141JDFC&lt;BR /&gt;Last Failover at: 00:52:22 UTC Nov 18 2021&lt;BR /&gt;This host: Secondary - Active&lt;BR /&gt;Active time: 6830576 (sec)&lt;BR /&gt;slot 0: ASA5525 hw/sw rev (3.1/9.8(1)) status (Up Sys)&lt;BR /&gt;Interface outside (172.17.17.250): Normal (Monitored)&lt;BR /&gt;Interface inside (172.16.10.250): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.1.1): Normal (Waiting)&lt;BR /&gt;slot 1: SFR5525 hw/sw rev (N/A/6.4.0.7-53) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 6.4.0.7-53, Up, (Monitored)&lt;BR /&gt;slot 1: SFR5525 hw/sw rev (N/A/6.4.0.7-53) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 6.4.0.7-53, Up, (Monitored)&lt;BR /&gt;Other host: Primary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5525 hw/sw rev (3.1/9.8(1)) status (Up Sys)&lt;BR /&gt;Interface outside (172.17.17.251): Normal (Monitored)&lt;BR /&gt;Interface inside (172.16.10.251): Normal (Monitored)&lt;BR /&gt;Interface management (0.0.0.0): Normal (Waiting)&lt;BR /&gt;slot 1: SFR5525 hw/sw rev (N/A/6.4.0.7-53) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 6.4.0.7-53, Up, (Monitored)&lt;BR /&gt;slot 1: SFR5525 hw/sw rev (N/A/6.4.0.7-53) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 6.4.0.7-53, Up, (Monitored)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : FAILOVER GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 1156191556 0 946779 151&lt;BR /&gt;sys cmd 910721 0 910720 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 720511659 0 23188 66&lt;BR /&gt;UDP conn 412556080 0 12700 84&lt;BR /&gt;ARP tbl 12085 0 16 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 9341 0 4 0&lt;BR /&gt;VPN IKEv1 P2 112120 0 18 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 7359449 0 40 0&lt;BR /&gt;SIP Tx 7359208 0 49 0&lt;BR /&gt;SIP Pinhole 7358657 0 39 1&lt;BR /&gt;Route Session 306 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1930 0 5 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 17 946946&lt;BR /&gt;Xmit Q: 0 65 1174852500&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 10:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546064#M1087088</guid>
      <dc:creator>kaleemullahbilal1</dc:creator>
      <dc:date>2022-02-05T10:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546123#M1087091</link>
      <description>&lt;P&gt;before failing back to primary firewall make sure both units see each other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;show failover | i host&lt;/PRE&gt;
&lt;P&gt;this above command will tell you if the both units can see each other. in case if the command tell you&lt;/P&gt;
&lt;P&gt;the "Other host primary - Failed" in that case you need to figure out what causing this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;other command which can help you is&lt;/P&gt;
&lt;PRE&gt;show failover state&lt;/PRE&gt;
&lt;P&gt;this command will tell us if the issue was occured due to any Comm Failure. If this is the case you better check the back to back cable/if the swiches are setup in between make sure the cables are connected or the check on the swtiches the primary interfaces and the secondary interface mac address are learned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can check the command&lt;/P&gt;
&lt;PRE&gt;show failover history&lt;/PRE&gt;
&lt;P&gt;this command will tell you the break down of the event the occured during this time when the HA unit failed from parimary to secodnadry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to fail back the firewall you need to ssh or console or if on ASDM to fail it back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is the method from SSH.&lt;/P&gt;
&lt;P&gt;prior to failing back make sure both HA are in good health and see each other with any issue. for example they should be looking like this.&lt;/P&gt;
&lt;PRE&gt;show failover | i host
        This host: Primary - Standby
        Other host: Secondary - Active&lt;/PRE&gt;
&lt;P&gt;you connect to ssh on the standby firewall and give command&lt;/P&gt;
&lt;PRE&gt;failover active&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or you can connected to standby fireall (which is active as active firewall)&lt;/P&gt;
&lt;P&gt;you can give command on this firewall&lt;/P&gt;
&lt;PRE&gt;no failover active&lt;/PRE&gt;
&lt;P&gt;this will force the firewall to fall back to primary unite and make it active.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Feb 2022 16:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546123#M1087091</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-02-05T16:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546418#M1087115</link>
      <description>&lt;P&gt;Thanks for the Quick reply and giving the detailed information, how do i check total number of anyconnect users configured on asa?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 05:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546418#M1087115</guid>
      <dc:creator>kaleemullahbilal1</dc:creator>
      <dc:date>2022-02-07T05:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546925#M1087135</link>
      <description>&lt;P&gt;To check how many licences you have for your anyconnect. Give command "show version" in it there will be the information how many anyconnect licences you have purchased.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to check how many user are connected to anyconnect give command "show vpn-session detail anyconnect" or "show vpn-session summary"&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 21:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4546925#M1087135</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-02-07T21:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 - Failover troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4547119#M1087150</link>
      <description>&lt;P&gt;Thanks for the reply, my actual question is how can i see number of Anyconnect users configured on the ASA with the there level of access not the connected users.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 04:50:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-troubleshooting/m-p/4547119#M1087150</guid>
      <dc:creator>kaleemullahbilal1</dc:creator>
      <dc:date>2022-02-08T04:50:37Z</dc:date>
    </item>
  </channel>
</rss>

