<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 9.18(2)5, Configuration Replication Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727954#M1095360</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/221759"&gt;@stephan.ochs&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Configuration looks good to me. I would try with removal of encryption key, to see if that makes any difference. If that doesn't provide appropriate results, and given that 3100 is fairly new platform, I would open a TAC case to figure out what is going on.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
    <pubDate>Fri, 25 Nov 2022 07:58:18 GMT</pubDate>
    <dc:creator>Milos_Jovanovic</dc:creator>
    <dc:date>2022-11-25T07:58:18Z</dc:date>
    <item>
      <title>ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4725849#M1095217</link>
      <description>&lt;P&gt;I am doing first tests with the new Secure Firewall 3120 (in application mode with ASA 9.18.2.5).&lt;BR /&gt;In these tests I am experiencing configuration replication issues in system context.&lt;BR /&gt;When creating a new context only a part of the context configuration is replicated to the standby.&lt;BR /&gt;In detail, only the "config-url disk0:/..." is replicated.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Looks like this on active:&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;context testtest&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;member testtest&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;allocate-interface Port-channel2.11 visible&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;allocate-interface Port-channel2.12 visible&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;allocate-interface Port-channel3.11 visible&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;config-url disk0:/testtest.cfg&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;storage-url private disk0:/private-storage/testtest disk0p&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;storage-url shared disk0:/shared-storage disk0s&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;But on standby only this :&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;context testtest&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; config-url disk0:/ctx_testtest.cfg&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;It can only be corrected by doing the configuration on both.&lt;BR /&gt;With corresponding warnings on standby about configuration replication.&lt;BR /&gt;Or rebooting standby to get a full replication from active to standby after reboot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Every other configuration in system context and in every other context is replicated to standby correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anybody else have this issue?&lt;BR /&gt;And maybe has solved it?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 12:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4725849#M1095217</guid>
      <dc:creator>stephan.ochs</dc:creator>
      <dc:date>2022-11-22T12:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4726119#M1095249</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/221759"&gt;@stephan.ochs&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Could you please share configuration from both devices, as it is today (where it doesn work)? I would like to see failover configuration, interface configuration, and the output of "show flash".&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 19:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4726119#M1095249</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-22T19:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727952#M1095359</link>
      <description>&lt;P&gt;Hello Milos&lt;BR /&gt;Sorry for the late reply. But I did an update to 9.18.2.7 before re-testing, hoping it would help. Unfortunately it didn't...&lt;BR /&gt;Here is the relevant part of my configuration, identical on primary/active and secondary/standby (&lt;SPAN&gt;sensitive data as VLAN and IP addresses are replaced by other values&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;PRE&gt;interface Port-channel1&lt;BR /&gt;description LAN/STATE Failover Interface&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/15&lt;BR /&gt; channel-group 1 mode active&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/16&lt;BR /&gt; channel-group 1 mode active&lt;BR /&gt;!&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit [primary|secondary]&lt;BR /&gt;failover lan interface failover Port-channel1&lt;BR /&gt;failover key *****&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link failover Port-channel1&lt;BR /&gt;failover interface ip failover 10.10.10.10 255.255.255.248 standby 10.10.10.11&lt;BR /&gt;failover wait-disable&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel2&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel2.100&lt;BR /&gt; vlan 100&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel2.101&lt;BR /&gt; vlan 101&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel2.102&lt;BR /&gt; vlan 102&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel3&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel3.102&lt;BR /&gt; vlan 102&lt;BR /&gt;!&lt;/PRE&gt;&lt;P&gt;Quick configuration test on primary/active:&lt;/P&gt;&lt;PRE&gt;.../pri/act(config)# context testtest&lt;BR /&gt;Creating context 'testtest'... Done. (5)&lt;BR /&gt;.../pri/act(config-ctx)# member testtest&lt;BR /&gt;.../pri/act(config-ctx)# allocate-interface Port-channel2.100 visible&lt;BR /&gt;.../pri/act(config-ctx)# allocate-interface Port-channel2.101 visible&lt;BR /&gt;.../pri/act(config-ctx)# allocate-interface Port-channel3.102 visible&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;Configuration seen on secondary/standby:&lt;/P&gt;&lt;PRE&gt;context testtest&lt;BR /&gt;!&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 07:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727952#M1095359</guid>
      <dc:creator>stephan.ochs</dc:creator>
      <dc:date>2022-11-25T07:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727954#M1095360</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/221759"&gt;@stephan.ochs&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Configuration looks good to me. I would try with removal of encryption key, to see if that makes any difference. If that doesn't provide appropriate results, and given that 3100 is fairly new platform, I would open a TAC case to figure out what is going on.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 07:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727954#M1095360</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-25T07:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727964#M1095361</link>
      <description>&lt;P&gt;Hi Milos&lt;BR /&gt;I will give it a try, but I don't think, changing the key will help.&lt;BR /&gt;Every other configuration in system context and any other context are replicated.&lt;BR /&gt;&lt;SPAN&gt;Apparently it only affects some commands within configuration of contexts.&lt;/SPAN&gt;&lt;BR /&gt;"member ...", "allocate-interface ...", "storage-url ...".&amp;nbsp;Maybe others I didn't use, yet.&lt;BR /&gt;The only command, that is replicated, is "config-url ..." which leads in erased interfaces in the context configuration on standby.&lt;BR /&gt;Yes, 3100 is fairly new, but it is an issue that should have been hit by any administrator yet, because of it's huge impact.&lt;BR /&gt;So I wonder, why I didn't find anything about it (bug search and community).&lt;BR /&gt;I will keep on searching and open a TAC case.&lt;/P&gt;&lt;P&gt;Thanks an best regards&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 08:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4727964#M1095361</guid>
      <dc:creator>stephan.ochs</dc:creator>
      <dc:date>2022-11-25T08:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4728032#M1095365</link>
      <description>&lt;P&gt;Finally found the corresponding bug description:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd54400" target="_blank" rel="noopener"&gt;CSCwd54400 : Bug Search Tool (cisco.com)&lt;/A&gt;&lt;BR /&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;SPAN&gt; NO workaround other than reloading the device&lt;BR /&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&amp;nbsp;3 Moderate (!!??!!)&lt;BR /&gt;I think, this is anything other than moderate.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 11:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4728032#M1095365</guid>
      <dc:creator>stephan.ochs</dc:creator>
      <dc:date>2022-11-25T11:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4730872#M1095544</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It seems that we have hit this bug too.&lt;/P&gt;&lt;P&gt;In our case workaround was "write standby" .&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 11:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4730872#M1095544</guid>
      <dc:creator>Branimir Turk</dc:creator>
      <dc:date>2022-12-01T11:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.18(2)5, Configuration Replication Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4730911#M1095545</link>
      <description>&lt;P&gt;Thank you for the hint, Branimir.&lt;BR /&gt;Didn't mention it.&lt;BR /&gt;But one should be aware, that it causes a short outage of standby device.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 12:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-18-2-5-configuration-replication-issue/m-p/4730911#M1095545</guid>
      <dc:creator>stephan.ochs</dc:creator>
      <dc:date>2022-12-01T12:03:20Z</dc:date>
    </item>
  </channel>
</rss>

