<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Failover - Detect service card failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/4707066#M1094382</link>
    <description>&lt;P&gt;Hello Ajay,&lt;/P&gt;&lt;P&gt;I have the same case but I don't have an IPS module within my Cisco ASA and I got random failover with reason:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Detect service card failure&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Can you advise on this?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks,&lt;/DIV&gt;&lt;DIV class=""&gt;Tanios&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2022 07:14:08 GMT</pubDate>
    <dc:creator>tanios191</dc:creator>
    <dc:date>2022-10-21T07:14:08Z</dc:date>
    <item>
      <title>ASA Failover - Detect service card failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3711452#M14413</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running ASAs 9.8(2) in Act/Stdby mode. Recently, our primary ASA got rebooted and services got impacted. Upon checking checking failover history, we got the message -&amp;nbsp;Detect service card failure. Upon checking syslogs - we only got 2 messages of significance:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i)&amp;nbsp;Line protocol on interface changed state to down&lt;/P&gt;
&lt;P&gt;ii)&amp;nbsp;Line protocol on interface changed state to up&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe the inside interface went down or something but can someone please explain a bit more in detail about this since we are doing RCA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) What's "&lt;SPAN&gt;Detect service card failure" mean? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) What measures should we take in order to avoid this happening again in future?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have attached a the failover output file for reference.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abhijit&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:16:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3711452#M14413</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2020-02-21T16:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover - Detect service card failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3711515#M14415</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;/U&gt;Hello Abhijeet,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The service card refers to any software based IPS module installed in the ASA, for example IPS module. If it fails or it is too busy to respond to the ASA backplane hello packets, it is detected as a failover reason and failover would happen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The logs from Secondary device are from 13 Sep when I guess that the primary device reloaded, which is normal since it says that it has not heard from mate, and hence it became active. This happened around 21:55 on Sep 13th 2018.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The logs from Primary firewall wherein says service card failed looks like a transition phase message when it was initializing after the ASA reloaded.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The real issue here is on Sep 20th around 12:59 when the interface failed message appears on Primary Firewall and this comes from inside interface. That is where you need to focus apart from the reason behind the reason for primary firewall reload.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ajay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 09:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3711515#M14415</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-09-22T09:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover - Detect service card failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3712531#M14417</link>
      <description>&lt;P&gt;Hi Ajay,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your inputs. Yes, we do have an IPS module built-in the ASA, though we dont use it.. Can you please let me know if there are any preventive measures, or any commands which we configure to avoid this incident happening again?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Abhijit&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 00:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3712531#M14417</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-09-25T00:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover - Detect service card failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3712695#M14418</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you wish to remove the IPS card from failover monitoring,&amp;nbsp;you can remove the failover monitoring of the IPS module:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;no monitor-interface service-module&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200944-Disable-Service-Module-Monitoring-on-ASA.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200944-Disable-Service-Module-Monitoring-on-ASA.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 09:38:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/3712695#M14418</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-09-25T09:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover - Detect service card failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/4707066#M1094382</link>
      <description>&lt;P&gt;Hello Ajay,&lt;/P&gt;&lt;P&gt;I have the same case but I don't have an IPS module within my Cisco ASA and I got random failover with reason:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Detect service card failure&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Can you advise on this?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks,&lt;/DIV&gt;&lt;DIV class=""&gt;Tanios&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 07:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-detect-service-card-failure/m-p/4707066#M1094382</guid>
      <dc:creator>tanios191</dc:creator>
      <dc:date>2022-10-21T07:14:08Z</dc:date>
    </item>
  </channel>
</rss>

