<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA stops forwarding traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335642#M1123020</link>
    <description>&lt;P&gt;Thanks for your replies.&lt;/P&gt;&lt;P&gt;We stopped forwarding traffic to the sfr module, and disabled the module itself, yesterday morning and I believe this has resolved the issue.&lt;/P&gt;&lt;P&gt;Pretty sure&amp;nbsp; had shut the module down in a previous attempt to resolve the same issue some months ago, but didn't remove the forwarding (no sfr fail-open) that time.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Oct 2025 09:45:02 GMT</pubDate>
    <dc:creator>jfnk</dc:creator>
    <dc:date>2025-10-03T09:45:02Z</dc:date>
    <item>
      <title>ASA stops forwarding traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335125#M1123000</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;We have a pair of ASA5516-X devices, running as an active/standby pair. Several times a day, the active device will stop forwarding traffic so all users lose connectivity to all data, applications and services. There is no error message in the ASA log, and all networks remain up - that is to say it's still possible to connect to the ASA, and on the ASA you can verify that the Internet connection is still up and running - but the ASA simply stops forwarding traffic between networks. The failures do not occur after a set time, it is an intermittent (but too frequent) issue.&lt;BR /&gt;&lt;BR /&gt;The fix is to switch the active ASA off (or do a reload) so the standby device takes over as active. Connectivity is restored but a few hours later the same happens and we repeat the process.&lt;/P&gt;&lt;P&gt;This is a problem we have had in the past but the devices have been stable since March, around the time we upgraded to 9.16(4)82. This weekend I upgrade to 9.16(4)85, as recommended, and the problem returned. We have rolled back to 9.16(4)82, but the problem remains.&lt;/P&gt;&lt;P&gt;I have a case open with TAC, but they don't have any immediate idea so it's just a case of gathering info when the problem happens (but can't spend long doing that as we need to restore the service qiuckly)&lt;/P&gt;&lt;P&gt;Anyone had a similar issue?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 15:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335125#M1123000</guid>
      <dc:creator>jfnk</dc:creator>
      <dc:date>2025-10-01T15:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA stops forwarding traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335135#M1123001</link>
      <description>&lt;P&gt;What kind of traffic is this ASA processing?&lt;/P&gt;
&lt;P&gt;When you have an issue, have you collected any Logs from the device?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show processes cpu-usage&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show blocks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show perfmon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show conn count&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show xlate count (if nat involved)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, check the troubleshooting guide :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113185-asaperformance.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113185-asaperformance.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;When you failover, the issue is resolved, and at that time, the secondary becomes active (after some time, it also stops processing traffic).&lt;/P&gt;
&lt;P&gt;Check on the connected switches, also any Logs, and check any interface drops&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 15:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335135#M1123001</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-10-01T15:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA stops forwarding traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335518#M1123016</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/eos-eol-notice-c51-744798.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/eos-eol-notice-c51-744798.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 17:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335518#M1123016</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-10-02T17:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA stops forwarding traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335642#M1123020</link>
      <description>&lt;P&gt;Thanks for your replies.&lt;/P&gt;&lt;P&gt;We stopped forwarding traffic to the sfr module, and disabled the module itself, yesterday morning and I believe this has resolved the issue.&lt;/P&gt;&lt;P&gt;Pretty sure&amp;nbsp; had shut the module down in a previous attempt to resolve the same issue some months ago, but didn't remove the forwarding (no sfr fail-open) that time.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 09:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335642#M1123020</guid>
      <dc:creator>jfnk</dc:creator>
      <dc:date>2025-10-03T09:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA stops forwarding traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335646#M1123021</link>
      <description>&lt;P&gt;glad all good and resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 10:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-forwarding-traffic/m-p/5335646#M1123021</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-10-03T10:10:32Z</dc:date>
    </item>
  </channel>
</rss>

