<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4781570#M1098174</link>
    <description>&lt;P&gt;Very relevant info here...&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/what-protocol-does-ha-in-cisco-asa-uses/td-p/3752187" target="_blank" rel="noopener"&gt;Solved: What protocol does HA in cisco ASA uses??? - Cisco Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Shared with the Failover Link&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Sharing a failover link is the best way to conserve interfaces. However, you must consider a dedicated interface for the state link and failover link, if you have a large configuration and a high traffic network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Dedicated Interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You can use a dedicated data interface (physical, redundant, or EtherChannel) for the state link. For an EtherChannel used as the state link, to prevent out-of-order packets, only one interface in the EtherChannel is used. If that interface fails, then the next interface in the EtherChannel is used.&lt;/P&gt;&lt;P&gt;Connect a dedicated state link in one of the following two ways:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Using a switch, with no other device on the same network segment (broadcast domain or VLAN) as the failover interfaces of the&amp;nbsp;ASAdevice.&lt;/LI&gt;&lt;LI&gt;Using an Ethernet cable to connect the appliances directly, without the need for an external switch.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you do not use a switch between the units, if the interface fails, the link is brought down on both peers. This condition may hamper troubleshooting efforts because you cannot easily determine which unit has the failed interface and caused the link to come down.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;ASA&amp;nbsp;supports Auto-MDI/MDIX on its copper Ethernet ports, so you can either use a crossover cable or a straight-through cable. If you use a straight-through cable, the interface automatically detects the cable and swaps one of the transmit/receive pairs to MDIX.&lt;/P&gt;&lt;P&gt;For optimum performance when using long distance failover, the latency for the state link should be less than 10 milliseconds and no more than 250 milliseconds. If latency is more than 10 milliseconds, some performance degradation occurs due to retransmission of failover messages.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Avoiding Interrupted Failover and Data Links&lt;/P&gt;&lt;P&gt;We recommend that failover links and data interfaces travel through different paths to decrease the chance that all interfaces fail at the same time. If the failover link is down, the&amp;nbsp;ASA&amp;nbsp;can use the data interfaces to determine if a failover is required. Subsequently, the failover operation is suspended until the health of the failover link is restored.&lt;/P&gt;&lt;P&gt;See the following connection scenarios to design a resilient failover network.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario 1—Not Recommended&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If a single switch or a set of switches are used to connect both failover and data interfaces between two&amp;nbsp;ASAs, then when a switch or inter-switch-link is down, both&amp;nbsp;ASAs become active. Therefore, the following two connection methods shown in the following figures are NOT recommended.&lt;/P&gt;&lt;P&gt;Figure 1.&amp;nbsp;Connecting with a Single Switch—Not Recommended&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_0-1677176122646.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177256i5D9281C356443AA2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_0-1677176122646.jpeg" alt="jmaxwellUSAF_0-1677176122646.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure 2.&amp;nbsp;Connecting with a Double-Switch—Not Recommended&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_1-1677176122648.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177258iE96E2C7D4DC077CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_1-1677176122648.jpeg" alt="jmaxwellUSAF_1-1677176122648.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario 2—Recommended&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We recommend that failover links NOT use the same switch as the data interfaces. Instead, use a different switch or use a direct cable to connect the failover link, as shown in the following figures.&lt;/P&gt;&lt;P&gt;Figure 3.&amp;nbsp;Connecting with a Different Switch&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_2-1677176122649.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177257iA982B1FBAC5FC705/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_2-1677176122649.jpeg" alt="jmaxwellUSAF_2-1677176122649.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure 4.&amp;nbsp;Connecting with a Cable&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_3-1677176122652.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177259i9DD775BDA55CA522/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_3-1677176122652.jpeg" alt="jmaxwellUSAF_3-1677176122652.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 18:17:11 GMT</pubDate>
    <dc:creator>MicJameson1</dc:creator>
    <dc:date>2023-02-23T18:17:11Z</dc:date>
    <item>
      <title>HA ASA-5525 pair failed to send gratuitous ARPs during failover. Why?</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4781428#M1098173</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I performed a task as instructed by my senior, to reboot the primary ASA-5525 (9.14(3)), then when it returned online, to reboot the secondary. At the beginning, I believe I did execute "failover active", but I am not certain because I remember that I concluded it was irrelevant. I did reboot the primary ASA. I verified that this primary came back online by witnessing on this device a normal reaction to pressing "enter" a few times.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then on the secondary, I entered "failover active", waited for about 15 seconds, then rebooted the secondary-- The secondary went offline, then every connection lost connectivity that traversed the ASA-5525. Clearly the failover technology somehow failed, because it is confirmed that the connected devices did not receive gratuitous ARPs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The correct question now is-- &lt;STRONG&gt;In a HA ASA-5525 cluster, when executing "failover active", why would the active secondary device not send gratuitous ARPs to the downstream devices?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thank you.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 04:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4781428#M1098173</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-24T04:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4781570#M1098174</link>
      <description>&lt;P&gt;Very relevant info here...&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/what-protocol-does-ha-in-cisco-asa-uses/td-p/3752187" target="_blank" rel="noopener"&gt;Solved: What protocol does HA in cisco ASA uses??? - Cisco Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Shared with the Failover Link&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Sharing a failover link is the best way to conserve interfaces. However, you must consider a dedicated interface for the state link and failover link, if you have a large configuration and a high traffic network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Dedicated Interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You can use a dedicated data interface (physical, redundant, or EtherChannel) for the state link. For an EtherChannel used as the state link, to prevent out-of-order packets, only one interface in the EtherChannel is used. If that interface fails, then the next interface in the EtherChannel is used.&lt;/P&gt;&lt;P&gt;Connect a dedicated state link in one of the following two ways:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Using a switch, with no other device on the same network segment (broadcast domain or VLAN) as the failover interfaces of the&amp;nbsp;ASAdevice.&lt;/LI&gt;&lt;LI&gt;Using an Ethernet cable to connect the appliances directly, without the need for an external switch.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you do not use a switch between the units, if the interface fails, the link is brought down on both peers. This condition may hamper troubleshooting efforts because you cannot easily determine which unit has the failed interface and caused the link to come down.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;ASA&amp;nbsp;supports Auto-MDI/MDIX on its copper Ethernet ports, so you can either use a crossover cable or a straight-through cable. If you use a straight-through cable, the interface automatically detects the cable and swaps one of the transmit/receive pairs to MDIX.&lt;/P&gt;&lt;P&gt;For optimum performance when using long distance failover, the latency for the state link should be less than 10 milliseconds and no more than 250 milliseconds. If latency is more than 10 milliseconds, some performance degradation occurs due to retransmission of failover messages.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Avoiding Interrupted Failover and Data Links&lt;/P&gt;&lt;P&gt;We recommend that failover links and data interfaces travel through different paths to decrease the chance that all interfaces fail at the same time. If the failover link is down, the&amp;nbsp;ASA&amp;nbsp;can use the data interfaces to determine if a failover is required. Subsequently, the failover operation is suspended until the health of the failover link is restored.&lt;/P&gt;&lt;P&gt;See the following connection scenarios to design a resilient failover network.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario 1—Not Recommended&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If a single switch or a set of switches are used to connect both failover and data interfaces between two&amp;nbsp;ASAs, then when a switch or inter-switch-link is down, both&amp;nbsp;ASAs become active. Therefore, the following two connection methods shown in the following figures are NOT recommended.&lt;/P&gt;&lt;P&gt;Figure 1.&amp;nbsp;Connecting with a Single Switch—Not Recommended&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_0-1677176122646.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177256i5D9281C356443AA2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_0-1677176122646.jpeg" alt="jmaxwellUSAF_0-1677176122646.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure 2.&amp;nbsp;Connecting with a Double-Switch—Not Recommended&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_1-1677176122648.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177258iE96E2C7D4DC077CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_1-1677176122648.jpeg" alt="jmaxwellUSAF_1-1677176122648.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Scenario 2—Recommended&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We recommend that failover links NOT use the same switch as the data interfaces. Instead, use a different switch or use a direct cable to connect the failover link, as shown in the following figures.&lt;/P&gt;&lt;P&gt;Figure 3.&amp;nbsp;Connecting with a Different Switch&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_2-1677176122649.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177257iA982B1FBAC5FC705/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_2-1677176122649.jpeg" alt="jmaxwellUSAF_2-1677176122649.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure 4.&amp;nbsp;Connecting with a Cable&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmaxwellUSAF_3-1677176122652.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177259i9DD775BDA55CA522/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmaxwellUSAF_3-1677176122652.jpeg" alt="jmaxwellUSAF_3-1677176122652.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 18:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4781570#M1098174</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-23T18:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782878#M1098175</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (318).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177596iA860035A9EA5FB45/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (318).png" alt="Screenshot (318).png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;sorry it late reply but some times I need time to make test before reply&amp;nbsp;&lt;BR /&gt;anyway&lt;BR /&gt;I see you mention NSK in one side of ASA HA&amp;nbsp;&lt;BR /&gt;you can use&amp;nbsp;&lt;BR /&gt;etheranalyzer local interface inband limit-capture-frames 30 &amp;lt;&amp;lt;- do this in NSK when you do failover active in standby ASA to capture if the ASA send G-ARP or not.&amp;nbsp;&lt;BR /&gt;thanks&amp;nbsp;&lt;BR /&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 11:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782878#M1098175</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-02-26T11:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782904#M1098176</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt; "Generally, when a failover occurs, the new active unit takes over the active IP addresses and MAC addresses. Because network devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere on the network."....that is a quote from this guide - &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/ha-failover.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/ha-failover.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 17:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782904#M1098176</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-26T17:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782925#M1098177</link>
      <description>&lt;P&gt;You have located the essential literature for this issue. Thank you Rob!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Generally, when a failover occurs, the new active unit takes over the active IP addresses and MAC addresses. Because network devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere on the network."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This seems to imply that the connected devices' ARP and mac-address tables would hold identical entries for two interfaces, so all traffic destined to the HA pair would always exit 2 interfaces on any redundantly connected device. &lt;STRONG&gt;Is that correct?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 16:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782925#M1098177</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T16:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782926#M1098178</link>
      <description>&lt;P&gt;Thank you MHM.&lt;/P&gt;&lt;P&gt;This is very helpful, and clearly you put much work into this response.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 16:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782926#M1098178</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T16:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782928#M1098179</link>
      <description>&lt;P&gt;That not correct as I know' in active/standby the unti that be elect as new active always send g-arp&lt;/P&gt;
&lt;P&gt;Why ?&lt;/P&gt;
&lt;P&gt;Because it make SW know that the port to new active is change.&lt;/P&gt;
&lt;P&gt;That why I mention NSK and how you must detect G-ARP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some times this G-ARP missed and SW use previous port which lead to old active pair and hence packet drop.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 17:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782928#M1098179</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-02-26T17:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782931#M1098180</link>
      <description>&lt;P&gt;I now realize I did not fundamentally understand how "protocol 105" technology works. I thought it was the same as HSRP technology, it is NOT.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Generally, when a failover occurs, the new active unit takes over the active IP addresses and MAC addresses. Because network devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere on the network."&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/ha-failover.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/ha-failover.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 17:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782931#M1098180</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T17:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782935#M1098181</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt; from the book - Cisco ASA all in one&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 483px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177602i675D1258E585480B/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 488px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/177603iB9969584676F2CCB/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 17:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782935#M1098181</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-26T17:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782942#M1098182</link>
      <description>&lt;P&gt;&lt;STRONG&gt;is there a link to this text?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And because I own this physical text, &lt;STRONG&gt;may you provide the page #?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 18:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782942#M1098182</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T18:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782943#M1098183</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt; the top of page 662 - Cisco ASA All-in-One Next Generation Firewall, Third Edition.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 18:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782943#M1098183</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-26T18:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782947#M1098184</link>
      <description>&lt;P&gt;As a helpful and cautionary note,&lt;STRONG&gt; the below dynamic caused a "big nightmare" event that resulted in significant financial impact to an enterprise&lt;/STRONG&gt;. &lt;U&gt;It would be best for professionals to appreciate it by remember to&lt;STRONG&gt; configure VIRTUAL MAC ADDRESSES&lt;/STRONG&gt;&lt;/U&gt;...&lt;/P&gt;&lt;P&gt;Active/Standby IP Addresses and MAC Addresses&lt;BR /&gt;For Active/StandbyFailover,see the following for IPaddress and MAC address usage during a failover event:&lt;BR /&gt;1. The active unit always uses the primary unit's IP addresses and MAC addresses.&lt;BR /&gt;2. When the active unit fails over, the standby unit assumes the IP addresses and MAC addresses of the failed unit and begins passing traffic.&lt;BR /&gt;3. When the failed unit comes back online, it is now in a standby state and takes over the standby IPaddresses&lt;BR /&gt;and MAC addresses.&lt;/P&gt;&lt;P&gt;MAC Addresses and IP Addresses in Failover&lt;BR /&gt;However, if the secondary unit boots without detecting the primary unit, &lt;FONT color="#FF0000"&gt;then the secondary unit becomes the active unit and uses its own MAC addresses, because it does not know the primary unit MAC addresses. When the primary unit becomes available, the secondary (active) unit changes the MAC addresses to those of the primary unit, which can cause an interruption in your network traffic&lt;/FONT&gt;. Similarly, if you swap out the primary unit with new hardware, a new MAC address is used.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Virtual MAC addresses guard against this disruption&lt;/STRONG&gt;, because the active MAC addresses are known to the secondary unit at startup, and remain the same in the case of new primary unit hardware.&lt;FONT color="#FF0000"&gt; If you do not configure virtual MAC addresses, you might need to clear the ARP tables on connected routers to restore traffic flow. The ASA does not send gratuitous ARPs for static NAT addresses when the MAC address changes, so connected routers do not learn of the MAC address change for these addresses.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/ha-failover.html#ID-2107-00000416" target="_blank"&gt;CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide, 9.17 - Failover for High Availability [Cisco Secure Firewall ASA] - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 18:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782947#M1098184</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T18:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782961#M1098185</link>
      <description>&lt;P&gt;What is "NSK"?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 19:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782961#M1098185</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T19:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782966#M1098188</link>
      <description>&lt;P&gt;Hi Rob. I could not find this on google. &lt;STRONG&gt;May you tell me, or send me a link to what means "&lt;FONT color="#FF0000"&gt;cold standby"&lt;/FONT&gt; and "&lt;FONT color="#FF0000"&gt;active drain&lt;/FONT&gt;"&amp;nbsp; &amp;nbsp;in the below data?&lt;/STRONG&gt; Thank you!&lt;/P&gt;&lt;P&gt;FW/sec/stby# sh failo hist&lt;BR /&gt;==========================================================================&lt;BR /&gt;From State&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;To State&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;12:48:46 EST Feb 22 2023&lt;BR /&gt;Not Detected&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Negotiation&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;No Error&lt;/P&gt;&lt;P&gt;12:48:50 EST Feb 22 2023&lt;BR /&gt;Negotiation&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Cold Standby&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Detected an Active mate&lt;/P&gt;&lt;P&gt;12:48:52 EST Feb 22 2023&lt;BR /&gt;Cold Standby&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Sync Config&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Detected an Active mate&lt;/P&gt;&lt;P&gt;12:49:03 EST Feb 22 2023&lt;BR /&gt;Sync Config&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Sync File System&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Detected an Active mate&lt;/P&gt;&lt;P&gt;12:49:03 EST Feb 22 2023&lt;BR /&gt;Sync File System&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bulk Sync&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Detected an Active mate&lt;/P&gt;&lt;P&gt;12:49:16 EST Feb 22 2023&lt;BR /&gt;Bulk Sync&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Standby Ready&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Detected an Active mate&lt;/P&gt;&lt;P&gt;13:41:35 EST Feb 22 2023&lt;BR /&gt;Standby Ready&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Just Active&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Other unit wants me Active&lt;/P&gt;&lt;P&gt;13:41:35 EST Feb 22 2023&lt;BR /&gt;Just Active&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt; Active Drain&lt;/FONT&gt;&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Other unit wants me Active&lt;/P&gt;&lt;P&gt;13:41:35 EST Feb 22 2023&lt;BR /&gt;Active Drain&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active Applying Config&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Other unit wants me Active&lt;/P&gt;&lt;P&gt;13:41:35 EST Feb 22 2023&lt;BR /&gt;Active Applying Config&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active Config Applied&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Other unit wants me Active&lt;/P&gt;&lt;P&gt;13:41:35 EST Feb 22 2023&lt;BR /&gt;Active Config Applied Active Other unit wants me Active&lt;/P&gt;&lt;P&gt;13:42:15 EST Feb 22 2023&lt;BR /&gt;Active Standby Ready Other unit wants me Standby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2023 20:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782966#M1098188</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-02-26T20:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: HA ASA-5525 pair failed to send gratuitous ARPs during failover. W</title>
      <link>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782967#M1098189</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt; table 3 in this guide &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-f-to-show-ipu-commands.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/show-f-to-show-ipu-commands.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table" border="1" width="100%"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR&gt;
&lt;TD width="9.887869520897045%" class="entry"&gt;
&lt;P class="p"&gt;Cold Standby&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="89.90825688073394%" class="entry"&gt;
&lt;P class="p"&gt;The unit waits for the peer to reach the Active state. When the peer unit reaches the Active state, this unit progresses to the Standby Config state. This is a transient state.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="table" border="1" width="100%"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR&gt;
&lt;TD width="15.494393476044852%" class="entry"&gt;
&lt;P class="p"&gt;Active Drain&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="84.40366972477065%" class="entry"&gt;
&lt;P class="p"&gt;Queues messages from the peer are discarded. This is a transient state.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Sun, 26 Feb 2023 20:06:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ha-asa-5525-pair-failed-to-send-gratuitous-arps-during-failover/m-p/4782967#M1098189</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-26T20:06:45Z</dc:date>
    </item>
  </channel>
</rss>

