<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic That's odd. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082491#M135088</link>
    <description>&lt;P&gt;That's odd.&lt;/P&gt;
&lt;P&gt;Have you conirmed that the source MAC address for the 192.168.x.x traffic is an ASA interface?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2017 03:50:52 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-06-02T03:50:52Z</dc:date>
    <item>
      <title>ASA 5525 FAILOVER PROBLEMS</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082488#M135083</link>
      <description>&lt;P&gt;Hey guys, here's a question.&lt;/P&gt;
&lt;P&gt;Last year, we&amp;nbsp;depolyed 2 ASAs, and they are configured as failover mode.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use these commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; failover interface ip lan_failover 192.168.1.1 255.255.255.0 standby 192.168.1.2&lt;BR /&gt;&amp;nbsp; failover interface ip stateful_failover 192.168.2.1 255.255.255.0 standby 192.168.2.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; interface Port-channel2&lt;BR /&gt;&amp;nbsp; lacp max-bundle 8&lt;BR /&gt;&amp;nbsp; nameif outside&lt;BR /&gt;&amp;nbsp; security-level 50&lt;BR /&gt;&amp;nbsp; ip address 10.30.14.251 255.255.248.0 standby 10.30.14.252&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But this week, we configured 2 new ASAs, still in failover mode, and these 4 ASAs are in the same subnet, we use the same configure, only different is the outside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; failover interface ip lan_failover 192.168.1.1 255.255.255.0 standby 192.168.1.2&lt;BR /&gt;&amp;nbsp; failover interface ip stateful_failover 192.168.2.1 255.255.255.0 standby 192.168.2.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; interface Port-channel2&lt;BR /&gt;&amp;nbsp; lacp max-bundle 8&lt;BR /&gt;&amp;nbsp; nameif outside&lt;BR /&gt;&amp;nbsp; security-level 50&lt;BR /&gt;&amp;nbsp; ip address 10.30.14.253 255.255.248.0 standby 10.30.14.254&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So, in&amp;nbsp;my opion, &amp;nbsp;the failover link is just connect to each other, it will not effect the whole network,&amp;nbsp;but when we capture the packet in broadcast domain, we found some 192.168.x.x packets, so is it OK? &amp;nbsp; Thx!~~~&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082488#M135083</guid>
      <dc:creator>ml12129</dc:creator>
      <dc:date>2019-03-12T09:27:00Z</dc:date>
    </item>
    <item>
      <title>How are your lan_failover and</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082489#M135084</link>
      <description>&lt;P&gt;How are your lan_failover and stateful_failover interfaces connected? i.e. is it a direct cable or via an intermediate switch?&lt;/P&gt;
&lt;P&gt;Generally we would not expect to see the ASA flood out any interface except the connected ones for a given subnet.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 08:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082489#M135084</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-01T08:10:05Z</dc:date>
    </item>
    <item>
      <title>Thanks for reply. Direct</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082490#M135085</link>
      <description>&lt;P&gt;Thanks for reply. Direct cable. 1st ASA's&amp;nbsp;G0/6 connect to 2nd ASA's G0/6. &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1st ASA's&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;G&lt;/SPAN&gt;&lt;SPAN&gt;0/7 connect to 2nd ASA's &lt;/SPAN&gt;&lt;SPAN&gt;G&lt;/SPAN&gt;&lt;SPAN&gt;0/7. &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 03:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082490#M135085</guid>
      <dc:creator>ml12129</dc:creator>
      <dc:date>2017-06-02T03:45:14Z</dc:date>
    </item>
    <item>
      <title>That's odd.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082491#M135088</link>
      <description>&lt;P&gt;That's odd.&lt;/P&gt;
&lt;P&gt;Have you conirmed that the source MAC address for the 192.168.x.x traffic is an ASA interface?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 03:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-failover-problems/m-p/3082491#M135088</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-02T03:50:52Z</dc:date>
    </item>
  </channel>
</rss>

