<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Multiple context failover normal (waiting) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3718782#M11956</link>
    <description>Hi Community,&lt;BR /&gt;&lt;BR /&gt;Problem was solved reloading both ASAs.&lt;BR /&gt;Now looks fine!!!&lt;BR /&gt;Group 1 last failover at: 08:34:44 UTC Oct 3 2018&lt;BR /&gt;Group 2 last failover at: 08:36:21 UTC Oct 3 2018&lt;BR /&gt;&lt;BR /&gt;  This host:    Primary&lt;BR /&gt;  Group 1       State:          Active&lt;BR /&gt;                Active time:    1418 (sec)&lt;BR /&gt;  Group 2       State:          Standby Ready&lt;BR /&gt;                Active time:    96 (sec)&lt;BR /&gt;&lt;BR /&gt;		slot 0: ASA5555 hw/sw rev (3.1/9.8(2)38) status (Up Sys)&lt;BR /&gt;		  admin Interface management (172.27.0.235): Normal (Monitored)&lt;BR /&gt;		  DATACENTER Interface inside (172.16.254.1): Normal (Monitored)&lt;BR /&gt;		  DATACENTER Interface outside (172.16.254.17): Normal (Monitored)&lt;BR /&gt;		slot 1: SFR5555 hw/sw rev (N/A/6.2.2-81) status (Up/Up)&lt;BR /&gt;&lt;BR /&gt;Best Regards</description>
    <pubDate>Wed, 03 Oct 2018 21:48:25 GMT</pubDate>
    <dc:creator>erickflamenco</dc:creator>
    <dc:date>2018-10-03T21:48:25Z</dc:date>
    <item>
      <title>ASA Multiple context failover normal (waiting)</title>
      <link>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3717804#M11953</link>
      <description>&lt;P&gt;Hi Pros,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have 2 ASA firewall in multiple context but the first context keep stuck in normal (waiting)&lt;/P&gt;
&lt;P&gt;00INFASA05/pri/act# sh fail&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: Failover GigabitEthernet1/4 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 3 of 516 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.8(2)38, Mate 9.8(2)38&lt;BR /&gt;Serial Number: Ours FCH1234J3CX, Mate FCH56787BCX&lt;BR /&gt;Group 1 last failover at: 10:37:30 UTC Oct 2 2018&lt;BR /&gt;Group 2 last failover at: 11:10:47 UTC Oct 1 2018&lt;/P&gt;
&lt;P&gt;This host: Primary&lt;BR /&gt; Group 1 State: Active&lt;BR /&gt; Active time: 323 (sec)&lt;BR /&gt; Group 2 State: Active&lt;BR /&gt; Active time: 84725 (sec)&lt;/P&gt;
&lt;P&gt;slot 0: ASA5555 hw/sw rev (3.1/9.8(2)38) status (Up Sys)&lt;BR /&gt; admin Interface management (172.27.0.235): Normal (Monitored)&lt;BR /&gt; DATACENTER Interface inside (172.16.254.1): Normal (Waiting)&lt;BR /&gt; DATACENTER Interface outside (172.16.254.17): Normal (Waiting)&lt;BR /&gt; slot 1: SFR5555 hw/sw rev (N/A/6.2.2-81) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.2-81, Up, (Monitored)&lt;BR /&gt; slot 1: SFR5555 hw/sw rev (N/A/6.2.2-81) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.2-81, Up, (Monitored)&lt;/P&gt;
&lt;P&gt;Other host: Secondary&lt;BR /&gt; Group 1 State: Standby Ready&lt;BR /&gt; Active time: 66 (sec)&lt;BR /&gt; Group 2 State: Standby Ready&lt;BR /&gt; Active time: 5544 (sec)&lt;/P&gt;
&lt;P&gt;slot 0: ASA5555 hw/sw rev (1.0/9.8(2)38) status (Up Sys)&lt;BR /&gt; admin Interface management (172.27.0.236): Normal (Monitored)&lt;BR /&gt; DATACENTER Interface inside (172.16.254.2): Normal (Waiting)&lt;BR /&gt; DATACENTER Interface outside (172.16.254.18): Normal (Waiting)&lt;BR /&gt; slot 1: SFR5555 hw/sw rev (N/A/6.2.2-81) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.2-81, Up, (Monitored)&lt;BR /&gt; slot 1: SFR5555 hw/sw rev (N/A/6.2.2-81) status (Up/Up)&lt;BR /&gt; ASA FirePOWER, 6.2.2-81, Up, (Monitored)&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : statelink GigabitEthernet1/5 (up)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ping works fine&lt;/P&gt;
&lt;P&gt;00INFASA05/DATACENTER# ping 172.16.254.2&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 172.16.254.2, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt; 00INFASA05/DATACENTER# ping 172.16.254.18&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 172.16.254.18, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The inside and outside interface are port-channel interfaces connected to N9K (ASA1-N9K1 and ASA2-N9K2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Po10 inside and Po20 outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;00INFASA05/pri/act# sh port-channel summ&lt;BR /&gt;Flags: D - down P - bundled in port-channel&lt;BR /&gt; I - stand-alone s - suspended&lt;BR /&gt; H - Hot-standby (LACP only)&lt;BR /&gt; U - in use N - not in use, no aggregation/nameif&lt;BR /&gt; M - not in use, no aggregation due to minimum links not met&lt;BR /&gt; w - waiting to be aggregated&lt;BR /&gt;Number of channel-groups in use: 2&lt;BR /&gt;Group Port-channel Protocol Span-cluster Ports&lt;BR /&gt;------+-------------+---------+------------+------------------------------------&lt;BR /&gt;10 Po10(U) LACP No Gi0/0(P) Gi0/1(P) Gi0/2(P) Gi 0/3(P)&lt;BR /&gt;20 Po20(U) LACP No Gi0/4(P) Gi0/5(P) Gi0/6(P) Gi 0/7(P)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Port-channel from N9K-2&lt;/P&gt;
&lt;P&gt;00INFSWC04(config-if)# sh port-channel summ&lt;BR /&gt;Flags: D - Down P - Up in port-channel (members)&lt;BR /&gt; I - Individual H - Hot-standby (LACP only)&lt;BR /&gt; s - Suspended r - Module-removed&lt;BR /&gt; b - BFD Session Wait&lt;BR /&gt; S - Switched R - Routed&lt;BR /&gt; U - Up (port-channel)&lt;BR /&gt; p - Up in delay-lacp mode (member)&lt;BR /&gt; M - Not in use. Min-links not met&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Group Port- Type Protocol Member Ports&lt;BR /&gt; Channel&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;1 Po1(SU) Eth LACP Eth1/49(P) Eth1/50(P) Eth1/51(P)&lt;BR /&gt; Eth1/52(P)&lt;BR /&gt;2 Po2(SD) Eth LACP Eth1/53(D) Eth1/54(D)&lt;BR /&gt;10 Po10(SU) Eth LACP Eth1/2(P) Eth1/3(P) Eth1/4(P)&lt;BR /&gt; Eth1/5(P)&lt;BR /&gt;11 Po11(SD) Eth LACP Eth1/10(D)&lt;BR /&gt;20 Po20(SU) Eth LACP Eth1/6(P) Eth1/7(P) Eth1/8(P)&lt;BR /&gt; Eth1/9(P)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is FHELLO packets from ASA-1 never reach the secondary ASA-2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fover_parse: send_msg_ifc(): 172.16.254.1-&amp;gt;172.16.254.2 ifc 131074 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.3-&amp;gt;172.16.254.2 ifc 131074 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.4-&amp;gt;172.16.254.2 ifc 131074 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.5-&amp;gt;172.16.254.2 ifc 131074 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.17-&amp;gt;172.16.254.18 ifc 131075 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.19-&amp;gt;172.16.254.18 ifc 131075 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.20-&amp;gt;172.16.254.18 ifc 131075 cmd FHELLO&lt;BR /&gt;fover_parse: send_msg_ifc(): 172.16.254.21-&amp;gt;172.16.254.18 ifc 131075 cmd FHELLO&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The weird thing: I don´t know why there are 4 ip addresses sending FHello Messages&lt;/P&gt;
&lt;P&gt;with capture command&lt;/P&gt;
&lt;P&gt;10: 10:48:30.282684 172.16.254.17 &amp;gt; 172.16.254.18: ip-proto-105, length 44&lt;BR /&gt; 11: 10:48:30.282684 172.16.254.19 &amp;gt; 172.16.254.18: ip-proto-105, length 44&lt;BR /&gt; 12: 10:48:30.282700 172.16.254.20 &amp;gt; 172.16.254.18: ip-proto-105, length 44&lt;BR /&gt; 13: 10:48:30.282700 172.16.254.21 &amp;gt; 172.16.254.18: ip-proto-105, length&lt;/P&gt;
&lt;P&gt;Never a response from peer.&lt;/P&gt;
&lt;P&gt;The configured IP are:&lt;/P&gt;
&lt;P&gt;interface Port-channel10&lt;BR /&gt; description Interface Inside Contexto DATACENTER&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.16.254.1 255.255.255.240 standby 172.16.254.2 &lt;BR /&gt;!&lt;BR /&gt;interface Port-channel20&lt;BR /&gt; description Interface Outside Contexto DATACENTER&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 172.16.254.17 255.255.255.240 standby 172.16.254.18&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I have done&lt;/P&gt;
&lt;P&gt;I have shutdown 3 of 4 links int Po10 and Po20&lt;/P&gt;
&lt;P&gt;I have configured in N9K&lt;/P&gt;
&lt;P&gt;Int Po10&lt;/P&gt;
&lt;P&gt;switchport port type edge&lt;/P&gt;
&lt;P&gt;int Po20&lt;/P&gt;
&lt;P&gt;switchport port type edge&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have removed VLAN 890 and 891 from the peer-link beetwen N9K&lt;/P&gt;
&lt;P&gt;I have removed a link from the port-channel peer-link and use this link as a trunk port beetwen N9K1-N9K2 with&amp;nbsp;&lt;/P&gt;
&lt;P&gt;switchport trunk allowed vlan 890,891&lt;/P&gt;
&lt;P&gt;and N9K-1&lt;/P&gt;
&lt;P&gt;spanning-tree vlan 890,891 priority root primary&lt;/P&gt;
&lt;P&gt;and N9K-2&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;spanning-tree vlan 890,891 priority root&amp;nbsp;secondary&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No luck!!! failover still normal (waiting)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Management interface in admin context connected to IOS switch, looks fine:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin Interface management (172.27.0.235): Normal (Monitored)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin Interface management (172.27.0.236): Normal (Monitored)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Some advise will be appreciated...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3717804#M11953</guid>
      <dc:creator>erickflamenco</dc:creator>
      <dc:date>2020-02-21T16:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Multiple context failover normal (waiting)</title>
      <link>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3717815#M11955</link>
      <description>&lt;P&gt;You need consider vPC best practice design with ASA cluster, i have attached presentation which has some good example to understand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 21:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3717815#M11955</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-02T21:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Multiple context failover normal (waiting)</title>
      <link>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3718782#M11956</link>
      <description>Hi Community,&lt;BR /&gt;&lt;BR /&gt;Problem was solved reloading both ASAs.&lt;BR /&gt;Now looks fine!!!&lt;BR /&gt;Group 1 last failover at: 08:34:44 UTC Oct 3 2018&lt;BR /&gt;Group 2 last failover at: 08:36:21 UTC Oct 3 2018&lt;BR /&gt;&lt;BR /&gt;  This host:    Primary&lt;BR /&gt;  Group 1       State:          Active&lt;BR /&gt;                Active time:    1418 (sec)&lt;BR /&gt;  Group 2       State:          Standby Ready&lt;BR /&gt;                Active time:    96 (sec)&lt;BR /&gt;&lt;BR /&gt;		slot 0: ASA5555 hw/sw rev (3.1/9.8(2)38) status (Up Sys)&lt;BR /&gt;		  admin Interface management (172.27.0.235): Normal (Monitored)&lt;BR /&gt;		  DATACENTER Interface inside (172.16.254.1): Normal (Monitored)&lt;BR /&gt;		  DATACENTER Interface outside (172.16.254.17): Normal (Monitored)&lt;BR /&gt;		slot 1: SFR5555 hw/sw rev (N/A/6.2.2-81) status (Up/Up)&lt;BR /&gt;&lt;BR /&gt;Best Regards</description>
      <pubDate>Wed, 03 Oct 2018 21:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3718782#M11956</guid>
      <dc:creator>erickflamenco</dc:creator>
      <dc:date>2018-10-03T21:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Multiple context failover normal (waiting)</title>
      <link>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3718961#M11957</link>
      <description>&lt;P&gt;Glad it was resolved by it self.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 07:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multiple-context-failover-normal-waiting/m-p/3718961#M11957</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-04T07:09:49Z</dc:date>
    </item>
  </channel>
</rss>

