<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5545 active/standby failover problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750027#M1096497</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see my FWs' information as below.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Wayne Wan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is for the Secondary (healthy one)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;/P&gt;&lt;P&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;/P&gt;&lt;P&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.12 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.2 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.6 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;/P&gt;&lt;P&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.101 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;/P&gt;&lt;P&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;/P&gt;&lt;P&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number:&lt;BR /&gt;Last Failover at: 00:42:29 HKST Dec 21 2022&lt;BR /&gt;This host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;BR /&gt;Other host: Primary - Active&lt;BR /&gt;Active time: 1411346 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 188157 0 59077632 0&lt;BR /&gt;sys cmd 188157 0 188157 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 0 0 55862238 0&lt;BR /&gt;UDP conn 0 0 2230639 0&lt;BR /&gt;ARP tbl 0 0 796597 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 0 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 0 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 23 62664268&lt;BR /&gt;Xmit Q: 0 1 188158&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is for the Primary (replaced one)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;/P&gt;&lt;P&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;/P&gt;&lt;P&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.11 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.1 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.5 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;/P&gt;&lt;P&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.102 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;/P&gt;&lt;P&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;/P&gt;&lt;P&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours&lt;BR /&gt;Last Failover at: 00:39:39 HKST Dec 21 2022&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 1411431 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;BR /&gt;Other host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 59082938 0 211943 0&lt;BR /&gt;sys cmd 188242 0 188242 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 55867219 0 22304 0&lt;BR /&gt;UDP conn 2230814 0 1081 0&lt;BR /&gt;ARP tbl 796653 0 315 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 9 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 25 3036007&lt;BR /&gt;Xmit Q: 0 30 59847409&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is for the Primary (defective one, now down and disconnected)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;BR /&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;BR /&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.11 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.1 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.5 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.102 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;BR /&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;BR /&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours&lt;BR /&gt;Last Failover at: 00:39:39 HKST Dec 21 2022&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 1411431 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;BR /&gt;Other host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 59082938 0 211943 0&lt;BR /&gt;sys cmd 188242 0 188242 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 55867219 0 22304 0&lt;BR /&gt;UDP conn 2230814 0 1081 0&lt;BR /&gt;ARP tbl 796653 0 315 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 9 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 25 3036007&lt;BR /&gt;Xmit Q: 0 30 59847409&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jan 2023 04:33:33 GMT</pubDate>
    <dc:creator>wayne wan</dc:creator>
    <dc:date>2023-01-06T04:33:33Z</dc:date>
    <item>
      <title>ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749387#M1096466</link>
      <description>&lt;P&gt;I have a pair of ASA5545 firewalls configured as Active/standby mode.&lt;/P&gt;&lt;P&gt;I added an addon network adapter card on them and configured the management&amp;nbsp;port on this card.&lt;BR /&gt;It's because the original management port needed to be the IPS(Firepower) port.&lt;/P&gt;&lt;P&gt;There was an incident occured as the programs on servers complained cannot connect to the default gateways.&lt;BR /&gt;I checked on the front panel , both firewalls ' active LED was on which indicated both are Active.&lt;/P&gt;&lt;P&gt;After further checking, there was hardware failure on the addon network adapter card occured on one of the firewall.&lt;BR /&gt;(I confirmed this as I can see the LED alarm is on the back panel and also I exported the configruation and compared with the saved version.&lt;BR /&gt;I saw the following GigbitEthernet1 lines are all missing on the defective firewall.&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0&lt;BR /&gt;management-only&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.10.102 255.255.255.0 standby 192.168.10.101&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;I connected the console port and find that both of them prompted the following messages.&lt;/P&gt;&lt;P&gt;WARING: Failover message decryption failure. Please make sure both units have the same failover shared key and crypto license&lt;BR /&gt;or system is not out of memory.&lt;/P&gt;&lt;P&gt;I rebooted both of the firwalls one by one and both active status still presisted.&lt;BR /&gt;The network is better but still, some of the programs will down due to the connection problem to gateways.&lt;BR /&gt;Finally, we need to power disconnected the good firewall , and leaving the defective firewall to be active. This made the network stable again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Does anyone know why the failover failed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks a lot!&lt;/P&gt;&lt;P&gt;Wayne Wan&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;This is my configuration&lt;/P&gt;&lt;P&gt;=====================&lt;BR /&gt;!&lt;BR /&gt;hostname fk01ssc-1&lt;BR /&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;BR /&gt;names&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.2&lt;BR /&gt;description Gigabit Connection to ek01ssc&lt;BR /&gt;vlan 2&lt;BR /&gt;nameif ek01ssc&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 10.73.2.11 255.255.255.240 standby 10.73.2.12&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.10&lt;BR /&gt;description Gigabit Connection to ek11ssc Core Zone&lt;BR /&gt;vlan 10&lt;BR /&gt;nameif ek11ssc_vlan_10&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 170.11.10.254 255.255.255.0 standby 170.11.10.253&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.11&lt;BR /&gt;description Gigabit Connection to ek11ssc Core Zone&lt;BR /&gt;vlan 11&lt;BR /&gt;nameif ek11ssc_vlan_11&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 170.11.11.254 255.255.255.0 standby 170.11.11.253&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.12&lt;BR /&gt;description Gigabit Connection to ek11ssc Core Zone&lt;BR /&gt;vlan 12&lt;BR /&gt;nameif ek11ssc_vlan_12&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 170.11.12.254 255.255.255.0 standby 170.11.12.253&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.13&lt;BR /&gt;description Gigabit Connection to ek11ssc Core Zone&lt;BR /&gt;vlan 13&lt;BR /&gt;nameif ek11ssc_vlan_13&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 170.11.13.254 255.255.255.0 standby 170.11.13.253&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.14&lt;BR /&gt;description Gigabit Connection to ek11ssc Core Zone&lt;BR /&gt;vlan 14&lt;BR /&gt;nameif ek11ssc_vlan_14&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 170.11.14.254 255.255.255.0 standby 170.11.14.253&lt;BR /&gt;!&lt;BR /&gt;:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/6&lt;BR /&gt;description LAN Failover Interface&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt;description STATE Failover Interface&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0&lt;BR /&gt;management-only&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.10.102 255.255.255.0 standby 192.168.10.101&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;:&lt;BR /&gt;:&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging standby&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging host management 192.168.10.181&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;mtu ek01ssc 1500&lt;BR /&gt;mtu ek11ssc_vlan_10 1500&lt;BR /&gt;mtu ek11ssc_vlan_11 1500&lt;BR /&gt;mtu ek11ssc_vlan_12 1500&lt;BR /&gt;mtu ek11ssc_vlan_13 1500&lt;BR /&gt;mtu ek11ssc_vlan_14 1500&lt;BR /&gt;mtu ek21ssc_vlan_20 1500&lt;BR /&gt;mtu ek21ssc_vlan_21 1500&lt;BR /&gt;mtu ek31ssc_vlan_30 1500&lt;BR /&gt;mtu ek31ssc_vlan_31 1500&lt;BR /&gt;mtu ek31ssc_vlan_32 1500&lt;BR /&gt;mtu ek31ssc_vlan_34 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;BR /&gt;monitor-interface ek01ssc&lt;BR /&gt;monitor-interface ek11ssc_vlan_10&lt;BR /&gt;monitor-interface ek11ssc_vlan_11&lt;BR /&gt;monitor-interface ek11ssc_vlan_12&lt;BR /&gt;monitor-interface ek11ssc_vlan_13&lt;BR /&gt;monitor-interface ek11ssc_vlan_14&lt;BR /&gt;monitor-interface ek21ssc_vlan_20&lt;BR /&gt;monitor-interface ek21ssc_vlan_21&lt;BR /&gt;monitor-interface ek31ssc_vlan_30&lt;BR /&gt;monitor-interface ek31ssc_vlan_31&lt;BR /&gt;monitor-interface ek31ssc_vlan_32&lt;BR /&gt;monitor-interface ek31ssc_vlan_34&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-792-152.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 32768&lt;BR /&gt;:&lt;BR /&gt;:&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 03:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749387#M1096466</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-05T03:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749442#M1096469</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx10845" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx10845&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 07:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749442#M1096469</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-01-05T07:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749463#M1096470</link>
      <description>&lt;P&gt;What type of "plugin" / module have you installed in the ASAs?&amp;nbsp; Are any other configuration being synchronised with the standby unit or are all configurations not replicated?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 08:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749463#M1096470</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-05T08:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749496#M1096476</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yes, I read this docuemnt before.&lt;/P&gt;&lt;P&gt;But I experienced this probelm twice in last year.&lt;/P&gt;&lt;P&gt;Before the first incident happened, I configured the failover in 2018 and I have already reloaded/failover a lot of times during testing and applying patch.&lt;BR /&gt;So I don't feel it's related.&lt;/P&gt;&lt;P&gt;Then, after first incident happened, I used a spare ASA5545 (which is one of the running pair in the test system) and I loaded the configure into it to replace the defective one.&lt;/P&gt;&lt;P&gt;After the replacemnet, I am sure I had done the failover testing.&lt;BR /&gt;Then the second incident happened. I checked all firewalls now, including the defective firewall, were enabled the Encryption license (3DES/AES) (using show ver to check).&lt;/P&gt;&lt;P&gt;Did I misunderstand something?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Wayne Wan&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749496#M1096476</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-05T09:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749504#M1096477</link>
      <description>&lt;P&gt;I also want to mention that after I loaded the configuration to the spare firewall.&lt;/P&gt;&lt;P&gt;I run the line "failover key &amp;lt;real key&amp;gt;" on both firewalls and let them to do the synchronization again.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 09:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749504#M1096477</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-05T09:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749867#M1096489</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1450042"&gt;@wayne wan&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;This is my configuration&lt;/P&gt;
&lt;P&gt;=====================&lt;BR /&gt;!&lt;BR /&gt;hostname &lt;STRONG&gt;fk01ssc-1&lt;BR /&gt;&lt;/STRONG&gt;&lt;SPAN&gt;failover&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover lan unit&lt;STRONG&gt; secondary&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover polltime unit msec 500 holdtime 2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover polltime interface msec 500 holdtime 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover key *****&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover link State_Link GigabitEthernet0/7&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;/SPAN&gt;&lt;BR /&gt;:&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I assume what you have posted is the Secondary ASA correct?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Can you post the following please from both FWs:&lt;BR /&gt;&lt;EM&gt;sh mode&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh cluster&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh interface ip brief&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh run failover&lt;/EM&gt;&lt;BR /&gt;sh failover&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 19:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749867#M1096489</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2023-01-05T19:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749990#M1096495</link>
      <description>&lt;P&gt;This the healthy firewall (default secondary)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;BR /&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;BR /&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.12 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.2 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.6 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.101 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;BR /&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;BR /&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours FCH1942J8FM, Mate FCH1942J8NT&lt;BR /&gt;Last Failover at: 00:42:29 HKST Dec 21 2022&lt;BR /&gt;This host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;BR /&gt;Other host: Primary - Active&lt;BR /&gt;Active time: 1411346 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 188157 0 59077632 0&lt;BR /&gt;sys cmd 188157 0 188157 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 0 0 55862238 0&lt;BR /&gt;UDP conn 0 0 2230639 0&lt;BR /&gt;ARP tbl 0 0 796597 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 0 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 0 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 23 62664268&lt;BR /&gt;Xmit Q: 0 1 188158&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the replaced one (default primary)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;BR /&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;BR /&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.11 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.1 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.5 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.102 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;BR /&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;BR /&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours FCH1942J8NT, Mate FCH1942J8FM&lt;BR /&gt;Last Failover at: 00:39:39 HKST Dec 21 2022&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 1411431 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;BR /&gt;Other host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 59082938 0 211943 0&lt;BR /&gt;sys cmd 188242 0 188242 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 55867219 0 22304 0&lt;BR /&gt;UDP conn 2230814 0 1081 0&lt;BR /&gt;ARP tbl 796653 0 315 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 9 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 25 3036007&lt;BR /&gt;Xmit Q: 0 30 59847409&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the defective one (original primary, now down)&lt;/P&gt;&lt;P&gt;term p 0&lt;BR /&gt;fk01ssc-1# show mode&lt;BR /&gt;Security context mode: single&lt;BR /&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;BR /&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.11 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset down down&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.254 YES CONFIG down down&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.1 YES unset down down&lt;BR /&gt;GigabitEthernet0/7 192.168.20.5 YES unset down down&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up down&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset down down&lt;BR /&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;BR /&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (Failed - No Switchover)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 12 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours FCH1945768K, Mate FCH1942J8FM&lt;BR /&gt;Last Failover at: 23:43:52 HKST Dec 20 2022&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 1414944 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): No Link (Waiting)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): No Link (Waiting)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): No Link (Waiting)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): No Link (Waiting)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): No Link (Waiting)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): No Link (Waiting)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): No Link (Waiting)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): No Link (Waiting)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): No Link (Waiting)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): No Link (Waiting)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): No Link (Waiting)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): No Link (Waiting)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;BR /&gt;Other host: Secondary - Failed&lt;BR /&gt;Active time: 12084 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Unknown/Unknown)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Unknown (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Unknown (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Unknown (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Unknown (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Unknown (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Unknown (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Unknown (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Unknown (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Unknown (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Unknown (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Unknown (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Unknown (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Unknown/Unknown)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Unknown, (Monitored)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (down)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 11137 0 4 0&lt;BR /&gt;sys cmd 5 0 4 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 10721 0 0 0&lt;BR /&gt;UDP conn 353 0 0 0&lt;BR /&gt;ARP tbl 57 0 0 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 0 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1 0 0 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 12 71&lt;BR /&gt;Xmit Q: 0 30 11203&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 02:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4749990#M1096495</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-06T02:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750021#M1096496</link>
      <description>&lt;P&gt;I made a more detail of my problem as below.&lt;/P&gt;&lt;P&gt;Hope it can be more understandable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Case 1) Occurred on APR-2022&lt;BR /&gt;fk01ssc-1 (Primary) is active and fk02ssc-1 (Secondary) has the defective add-on network adapter card.&lt;BR /&gt;The management port was configured on the add-on network adapter card.&lt;BR /&gt;Thus, syslog can still be transferred to the CSM for log consolation.&lt;/P&gt;&lt;P&gt;log in CSM&lt;BR /&gt;==========&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Lost Failover communications with mate on interface management&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing Interface management&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing on Interface management Passed&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing Interface ek31ssc_vlan_34&lt;BR /&gt;:&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing Interface ek21ssc_vlan_20&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Lost Failover communications with mate on interface ek31ssc_vlan_32&lt;BR /&gt;:&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Lost Failover communications with mate on interface ek31ssc_vlan_34&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing Interface ek01ssc&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing on interface ek31ssc_vlan_31 Passed&lt;BR /&gt;:&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing on interface ek01ssc Passed&lt;BR /&gt;:&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) Testing on interface ek11ssc_vlan_13 Status Undetermined&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) No respone from other firewall (reason code = 4) No response from failover mate&lt;BR /&gt;4/11/22 10:47:03AM Alert (Primary) No respone from other firewall (reason code = 3) No response from failover mate&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We connect the console to the firewall (not sure primary or secondary) , a lot of these message prompted.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Number of interfaces on Active and Standby are not consistent.&lt;BR /&gt;If the problem persists, you should disable and re-enable failover on the Standby.&lt;/P&gt;&lt;P&gt;After rebooted Secondary, since the add-on network adapter card is defective, we can see the rule cannot applied to the management interface. And also, the messages&lt;BR /&gt;“Number of interfaces on active and Standby are not consistent. If the problem persists, you should disable and re-enable failover on the standby.” got prompted after the Secondary was rebooted.&lt;/P&gt;&lt;P&gt;====================================================================================&lt;BR /&gt;Console on Secondary&lt;BR /&gt;====================================================================================&lt;BR /&gt;mtu management 1500&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;http 192.168.10.0 255.255.255.0 management&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;ssh 192.168.10.0 255.255.255.0 management&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;Number of interfaces on Active and Standby are not consistent.&lt;BR /&gt;If the problem persists, you should disable and re-enable failover on the Standby.&lt;BR /&gt;====================================================================================&lt;/P&gt;&lt;P&gt;We connected the console to the Primary(active) and observed the same error message was prompted. We checked on the front panel both active LEDs were on.&lt;/P&gt;&lt;P&gt;====================================================================================&lt;BR /&gt;Console on Primary&lt;BR /&gt;====================================================================================&lt;BR /&gt;Number of interfaces on Active and Standby are not consistent.&lt;BR /&gt;If the problem persists, you should disable and re-enable failover on the Standby.&lt;/P&gt;&lt;P&gt;Switching to Failed state&lt;BR /&gt;====================================================================================&lt;/P&gt;&lt;P&gt;My question for this case is that why the whole network seems so busy such that some of the program were down due to they cannot communicatie to the gateway when both firewalls were powered on.&lt;BR /&gt;The acitve firewall was up and the defective firewall is standby, there was no failover occurred.&lt;BR /&gt;I also experienced when use the ASDM to connect the gateway port, it take very long time.&lt;BR /&gt;The problem was quiet down when we power disconnected the defective firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Case 2) Occurred on DEC-2022&lt;/P&gt;&lt;P&gt;We replaced the defected firewall (Secondary) in APR. Now, on this case, the Primary firewall got the defective add-on network adapter card.&lt;/P&gt;&lt;P&gt;The symtopms were nearlly the same like the first case. Some of the programs were up and down between 04:52 PM to 06:09 PM .&lt;/P&gt;&lt;P&gt;After the incident was resloved, we checked on the CSM and find the follwoing log messages&lt;/P&gt;&lt;P&gt;12/20/22 04:52:49 PM Alert (Secondary) Switching to ACTIVE - HELLO not heard from mate.&lt;BR /&gt;12/20/22 06:16:16 PM Alert (Secondary) Failover interface Failed&lt;BR /&gt;12/20/22 06:16:16 PM Alert (Secondary) No response from other firewall (reason code = 4). No response from failover mate&lt;/P&gt;&lt;P&gt;The main difference is that at 18:09PM, we want to power disconnect the defective firewall to quiet down the problem base on last time's experience.&lt;BR /&gt;However, we did it on the wrong firewall, we power discconected the Secondary. We reveiwed the log after the incident and understand that The Secondary firewall is active and switched to active&lt;BR /&gt;at 04:52 since the primary got the defective add-on adapter card.&lt;/P&gt;&lt;P&gt;7 minutes later the Secondary is up. At that time period, we observed the network is still "busy" and programs were up and down.&lt;BR /&gt;Then we reload the Primary (the defective) one. Things became worse, many programs are totally down.&lt;BR /&gt;Then, we realised the Primary (the defective) is the real active and it needed to be up.&lt;/P&gt;&lt;P&gt;At this point, we observed the warning message prompted on both console .&lt;BR /&gt;"WARNING: Failover message decryption failure. Please make sure both units have the same failover shared key and crypto license or system is not out of memory"&lt;/P&gt;&lt;P&gt;So, we need to power disconnected the Secondary (healthy one) to make the network quiet down.&lt;/P&gt;&lt;P&gt;Finaly, we replaced the Primary firewall with a spare one to solve the problem.&lt;/P&gt;&lt;P&gt;For this case, the first part is the same as the case we faced in Apr.&lt;BR /&gt;For the second part, is that the "Failover message decryption failure" was triggered due to we stop the Secondary (healthy) firewall?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 04:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750021#M1096496</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-06T04:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750027#M1096497</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see my FWs' information as below.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Wayne Wan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is for the Secondary (healthy one)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;/P&gt;&lt;P&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;/P&gt;&lt;P&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.12 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.253 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.2 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.6 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;/P&gt;&lt;P&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.101 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;/P&gt;&lt;P&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;/P&gt;&lt;P&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number:&lt;BR /&gt;Last Failover at: 00:42:29 HKST Dec 21 2022&lt;BR /&gt;This host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;BR /&gt;Other host: Primary - Active&lt;BR /&gt;Active time: 1411346 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 188157 0 59077632 0&lt;BR /&gt;sys cmd 188157 0 188157 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 0 0 55862238 0&lt;BR /&gt;UDP conn 0 0 2230639 0&lt;BR /&gt;ARP tbl 0 0 796597 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 0 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 0 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 23 62664268&lt;BR /&gt;Xmit Q: 0 1 188158&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is for the Primary (replaced one)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;/P&gt;&lt;P&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;/P&gt;&lt;P&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.11 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.1 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.5 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;/P&gt;&lt;P&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.102 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;/P&gt;&lt;P&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;/P&gt;&lt;P&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours&lt;BR /&gt;Last Failover at: 00:39:39 HKST Dec 21 2022&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 1411431 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;BR /&gt;Other host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 59082938 0 211943 0&lt;BR /&gt;sys cmd 188242 0 188242 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 55867219 0 22304 0&lt;BR /&gt;UDP conn 2230814 0 1081 0&lt;BR /&gt;ARP tbl 796653 0 315 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 9 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 25 3036007&lt;BR /&gt;Xmit Q: 0 30 59847409&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is for the Primary (defective one, now down and disconnected)&lt;/P&gt;&lt;P&gt;show mode&lt;BR /&gt;Security context mode: single&lt;BR /&gt;fk01ssc-1# show cluster&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;fk01ssc-1# show cluster info&lt;BR /&gt;Clustering is not configured&lt;BR /&gt;fk01ssc-1# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/0.2 10.23.2.11 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/1.10 170.11.10.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.11 170.11.11.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.12 170.11.12.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.13 170.11.13.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/1.14 170.11.14.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/2.20 170.11.20.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/2.21 170.11.21.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet0/3.30 170.11.30.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.31 170.11.31.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.32 170.11.32.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/3.34 170.11.34.254 YES CONFIG up up&lt;BR /&gt;GigabitEthernet0/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet0/6 192.168.20.1 YES unset up up&lt;BR /&gt;GigabitEthernet0/7 192.168.20.5 YES unset up up&lt;BR /&gt;Internal-Control0/0 127.0.1.1 YES unset up up&lt;BR /&gt;Internal-Data0/0 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/1 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/2 unassigned YES unset up up&lt;BR /&gt;Internal-Data0/3 169.254.1.1 YES unset up up&lt;BR /&gt;Management0/0 unassigned YES unset up up&lt;BR /&gt;GigabitEthernet1/0 192.168.10.102 YES CONFIG up up&lt;BR /&gt;GigabitEthernet1/1 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/2 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/3 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;BR /&gt;fk01ssc-1# show run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN_Link GigabitEthernet0/6&lt;BR /&gt;failover polltime unit msec 500 holdtime 2&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover link State_Link GigabitEthernet0/7&lt;BR /&gt;failover interface ip LAN_Link 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;BR /&gt;failover interface ip State_Link 192.168.20.5 255.255.255.252 standby 192.168.20.6&lt;BR /&gt;fk01ssc-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: LAN_Link GigabitEthernet0/6 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 500 milliseconds, holdtime 2 seconds&lt;BR /&gt;Interface Poll frequency 500 milliseconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 13 of 316 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.6(4)42, Mate 9.6(4)42&lt;BR /&gt;Serial Number: Ours&lt;BR /&gt;Last Failover at: 00:39:39 HKST Dec 21 2022&lt;BR /&gt;This host: Primary - Active&lt;BR /&gt;Active time: 1411431 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.11): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.254): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.254): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.254): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.254): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.102): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0.12-17) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0.12-17, Up, (Monitored)&lt;BR /&gt;Other host: Secondary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5545 hw/sw rev (1.0/9.6(4)42) status (Up Sys)&lt;BR /&gt;Interface ek01ssc (10.23.2.12): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_10 (170.11.10.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_11 (170.11.11.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_12 (170.11.12.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_13 (170.11.13.253): Normal (Monitored)&lt;BR /&gt;Interface ek11ssc_vlan_14 (170.11.14.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_20 (170.11.20.253): Normal (Monitored)&lt;BR /&gt;Interface ek21ssc_vlan_21 (170.11.21.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_30 (170.11.30.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_31 (170.11.31.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_32 (170.11.32.253): Normal (Monitored)&lt;BR /&gt;Interface ek31ssc_vlan_34 (170.11.34.253): Normal (Monitored)&lt;BR /&gt;Interface management (192.168.10.101): Normal (Monitored)&lt;BR /&gt;slot 1: SFR5545 hw/sw rev (N/A/5.4.0-764) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.0-764, Up, (Monitored)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;Link : State_Link GigabitEthernet0/7 (up)&lt;BR /&gt;Stateful Obj xmit xerr rcv rerr&lt;BR /&gt;General 59082938 0 211943 0&lt;BR /&gt;sys cmd 188242 0 188242 0&lt;BR /&gt;up time 0 0 0 0&lt;BR /&gt;RPC services 0 0 0 0&lt;BR /&gt;TCP conn 55867219 0 22304 0&lt;BR /&gt;UDP conn 2230814 0 1081 0&lt;BR /&gt;ARP tbl 796653 0 315 0&lt;BR /&gt;Xlate_Timeout 0 0 0 0&lt;BR /&gt;IPv6 ND tbl 0 0 0 0&lt;BR /&gt;VPN IKEv1 SA 0 0 0 0&lt;BR /&gt;VPN IKEv1 P2 0 0 0 0&lt;BR /&gt;VPN IKEv2 SA 0 0 0 0&lt;BR /&gt;VPN IKEv2 P2 0 0 0 0&lt;BR /&gt;VPN CTCP upd 0 0 0 0&lt;BR /&gt;VPN SDI upd 0 0 0 0&lt;BR /&gt;VPN DHCP upd 0 0 0 0&lt;BR /&gt;SIP Session 0 0 0 0&lt;BR /&gt;SIP Tx 0 0 0 0&lt;BR /&gt;SIP Pinhole 0 0 0 0&lt;BR /&gt;Route Session 9 0 0 0&lt;BR /&gt;Router ID 0 0 0 0&lt;BR /&gt;User-Identity 1 0 1 0&lt;BR /&gt;CTS SGTNAME 0 0 0 0&lt;BR /&gt;CTS PAC 0 0 0 0&lt;BR /&gt;TrustSec-SXP 0 0 0 0&lt;BR /&gt;IPv6 Route 0 0 0 0&lt;BR /&gt;STS Table 0 0 0 0&lt;/P&gt;&lt;P&gt;Logical Update Queue Information&lt;BR /&gt;Cur Max Total&lt;BR /&gt;Recv Q: 0 25 3036007&lt;BR /&gt;Xmit Q: 0 30 59847409&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 04:33:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750027#M1096497</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-06T04:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750041#M1096498</link>
      <description>&lt;P&gt;Sorry, I had replied but I can't see my reply. Don't know if the configuration is too long?&lt;/P&gt;&lt;P&gt;I tried to attach here.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 05:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750041#M1096498</guid>
      <dc:creator>wayne wan</dc:creator>
      <dc:date>2023-01-06T05:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5545 active/standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750279#M1096500</link>
      <description>&lt;P&gt;Is the HA pair stable if you remove the failover key?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 11:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5545-active-standby-failover-problem/m-p/4750279#M1096500</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-06T11:25:05Z</dc:date>
    </item>
  </channel>
</rss>

