<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Active-Standby failover issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277570#M1120428</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1855185"&gt;@Ahmed843&lt;/a&gt;&amp;nbsp;wrote : &lt;EM&gt;&amp;gt;....&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;I just want to confirm that in case the secondary fails, the primary will become Active again&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Since there &lt;U&gt;&lt;STRONG&gt;was&lt;/STRONG&gt; &lt;/U&gt;a failover that cannot be exactly guaranteed, yet the outputs you provided&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; seem rather OK at first sight.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It's therefore always useful to configure a&lt;STRONG&gt; syslog server&lt;/STRONG&gt; on the active ASA, to have a central&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; place where logs are send and which can then be reviewed when there is a failover.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;You can also connect to the current active ASA with&amp;nbsp;&lt;A href="https://cway.cisco.com/cli/" target="_blank"&gt;https://cway.cisco.com/cli/&lt;/A&gt;&amp;nbsp; &amp;nbsp;(needs to be downloaded first)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;At the top right or left you can press (run) '&lt;EM&gt;System Diagnostics'&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; M.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 16:07:26 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2025-04-02T16:07:26Z</dc:date>
    <item>
      <title>ASA Active-Standby failover issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277526#M1120419</link>
      <description>&lt;P&gt;Hello Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The secondary ASA became Active for no apparent reason. Please find the show command output below. I just want to confirm that in case the secondary fails, the primary will become Active again. Also, I'd like to investigate the reason why this failover occurred in the first place.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;First ASA&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;VPN01# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: failover GigabitEthernet0/7 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 2 of 466 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.14(4)24, Mate 9.14(4)24&lt;BR /&gt;Serial Number: Ours xxxxxx1Q, Mate xxxxxxxZB&lt;BR /&gt;Last Failover at: 17:20:55 EDT Mar 20 2025&lt;BR /&gt;This host: Secondary - Active&lt;BR /&gt;Active time: 1097618 (sec)&lt;BR /&gt;slot 0: ASA5525 hw/sw rev (1.0/9.14(4)24) status (Up Sys)&lt;BR /&gt;Interface outside (1.1.1.1): Normal (Monitored)&lt;BR /&gt;Interface SHARED (X.X.255.6): Normal (Monitored)&lt;BR /&gt;Interface management (X.X.1.115): Normal (Not-Monitored)&lt;BR /&gt;Other host: Primary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5525 hw/sw rev (1.0/9.14(4)24) status (Up Sys)&lt;BR /&gt;Interface outside (1.1.1.1): Normal (Monitored)&lt;BR /&gt;Interface SHARED (X.X.255.206): Normal (Monitored)&lt;BR /&gt;Interface management (10.X.1.215): Normal (Not-Monitored)&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;VPN01# sho failover history&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1.png" style="width: 982px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242785iB96C70AD732E18EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN1.png" alt="VPN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Second ASA&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VPN01# show failover&lt;/STRONG&gt;&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: failover GigabitEthernet0/7 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 2 of 466 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.14(4)24, Mate 9.14(4)24&lt;BR /&gt;Serial Number: Ours XXXXXXZB, Mate XXXXXX1Q&lt;BR /&gt;Last Failover at: 17:23:12 EDT Mar 20 2025&lt;BR /&gt;This host: Primary - Standby Ready&lt;BR /&gt;Active time: 0 (sec)&lt;BR /&gt;slot 0: ASA5525 hw/sw rev (1.0/9.14(4)24) status (Up Sys)&lt;BR /&gt;Interface outside (1.1.1.1): Normal (Monitored)&lt;BR /&gt;Interface SHARED (x.x.x.206): Normal (Monitored)&lt;BR /&gt;Interface management (x.x.x.215): Normal (Not-Monitored)&lt;BR /&gt;Other host: Secondary - Active&lt;BR /&gt;Active time: 1098096 (sec)&lt;BR /&gt;slot 0: ASA5525 hw/sw rev (1.0/9.14(4)24) status (Up Sys)&lt;BR /&gt;Interface outside (1.1.1.1): Normal (Monitored)&lt;BR /&gt;Interface SHARED (x.x.x.6): Normal (Monitored)&lt;BR /&gt;Interface management (x.x.x.115): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VPN01# show failover history&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN2.png" style="width: 957px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242786i50B5B497C1049700/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN2.png" alt="VPN2.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 14:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277526#M1120419</guid>
      <dc:creator>Ahmed843</dc:creator>
      <dc:date>2025-04-02T14:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active-Standby failover issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277570#M1120428</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1855185"&gt;@Ahmed843&lt;/a&gt;&amp;nbsp;wrote : &lt;EM&gt;&amp;gt;....&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;I just want to confirm that in case the secondary fails, the primary will become Active again&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Since there &lt;U&gt;&lt;STRONG&gt;was&lt;/STRONG&gt; &lt;/U&gt;a failover that cannot be exactly guaranteed, yet the outputs you provided&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; seem rather OK at first sight.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It's therefore always useful to configure a&lt;STRONG&gt; syslog server&lt;/STRONG&gt; on the active ASA, to have a central&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; place where logs are send and which can then be reviewed when there is a failover.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;You can also connect to the current active ASA with&amp;nbsp;&lt;A href="https://cway.cisco.com/cli/" target="_blank"&gt;https://cway.cisco.com/cli/&lt;/A&gt;&amp;nbsp; &amp;nbsp;(needs to be downloaded first)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;At the top right or left you can press (run) '&lt;EM&gt;System Diagnostics'&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; M.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 16:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277570#M1120428</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-04-02T16:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active-Standby failover issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277604#M1120430</link>
      <description>&lt;P&gt;Thanks, marce1000 for the advice and also thanks for the (cway) tools.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 18:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover-issues/m-p/5277604#M1120430</guid>
      <dc:creator>Ahmed843</dc:creator>
      <dc:date>2025-04-02T18:58:51Z</dc:date>
    </item>
  </channel>
</rss>

