<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5585-X SSP40 Failover Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5585-x-ssp40-failover-problem/m-p/3080723#M135098</link>
    <description>&lt;P&gt;I have recently implemented ASA5585-X SFR SSP40 failover. Failover is up interfaces are monitored and configuration is replication and syncing from active to standby pair. Connectivity to core switch Cisco&amp;nbsp;6807-XL which is VSS&amp;nbsp;pair is as following;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firewall#1&lt;/P&gt;
&lt;P&gt;Firewall#1: Port Ten0/6 connected to Ten1/2/17 Core1 (Inside Port-channel)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#1: Port Ten0/7 connected to Ten2/2/17 Core2&amp;nbsp;(Inside Port-channel)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#1: Port Ten0/8 connected to Ten1/2/19 Core1 (Outside Interface)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#1: Port Ten0/9 connected to Ten0/9 Firewall2 (Ten0/9.1 LAN Failover, Ten0/9.2 Stateful Failover)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Firewall#2&lt;/P&gt;
&lt;P&gt;Firewall#2: Port Ten0/6 connected to Ten2/2/20 Core2 (Inside Port-channel)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#2: Port Ten0/7 connected to Ten1/2/20 Core1 (Inside Port-channel)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#2: Port Ten0/8 connected to Ten2/2/19 Core2 (Outside Interface)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#2: Port Ten0/9 connected to Ten0/9 Firewall2 (Ten0/9.1 LAN Failover, Ten0/9.2 Stateful Failover)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are running &lt;G class="gr_ gr_1739 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="1739" data-gr-id="1739"&gt;ospf&lt;/G&gt;&amp;nbsp;on core switches and ASA Firewall outside interfaces Ten0/8 on both firewalls are also configured in &lt;G class="gr_ gr_2129 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2129" data-gr-id="2129"&gt;ospf&lt;/G&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Firewall1 is primary and Firewall2 is the secondary pair in failover.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When Primary firewall is active &lt;G class="gr_ gr_2223 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2223" data-gr-id="2223"&gt;ospf&lt;/G&gt;&amp;nbsp;neighborship goes as well as I can not ping the subinterfaces created under inside interface port-channel&lt;/P&gt;
&lt;P&gt;when I make my secondary firewall as active &lt;G class="gr_ gr_2309 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2309" data-gr-id="2309"&gt;ospf&lt;/G&gt;&amp;nbsp;neighborship comes up and also I'm able to ping subinterfaces created for my inside networks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could be the problem, is it something to do with port-channel configuration or failover configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all in advance for kind response.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Asad.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:26:47 GMT</pubDate>
    <dc:creator>Atasawar1</dc:creator>
    <dc:date>2019-03-12T09:26:47Z</dc:date>
    <item>
      <title>ASA5585-X SSP40 Failover Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5585-x-ssp40-failover-problem/m-p/3080723#M135098</link>
      <description>&lt;P&gt;I have recently implemented ASA5585-X SFR SSP40 failover. Failover is up interfaces are monitored and configuration is replication and syncing from active to standby pair. Connectivity to core switch Cisco&amp;nbsp;6807-XL which is VSS&amp;nbsp;pair is as following;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firewall#1&lt;/P&gt;
&lt;P&gt;Firewall#1: Port Ten0/6 connected to Ten1/2/17 Core1 (Inside Port-channel)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#1: Port Ten0/7 connected to Ten2/2/17 Core2&amp;nbsp;(Inside Port-channel)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#1: Port Ten0/8 connected to Ten1/2/19 Core1 (Outside Interface)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#1: Port Ten0/9 connected to Ten0/9 Firewall2 (Ten0/9.1 LAN Failover, Ten0/9.2 Stateful Failover)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Firewall#2&lt;/P&gt;
&lt;P&gt;Firewall#2: Port Ten0/6 connected to Ten2/2/20 Core2 (Inside Port-channel)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#2: Port Ten0/7 connected to Ten1/2/20 Core1 (Inside Port-channel)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#2: Port Ten0/8 connected to Ten2/2/19 Core2 (Outside Interface)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firewall#2: Port Ten0/9 connected to Ten0/9 Firewall2 (Ten0/9.1 LAN Failover, Ten0/9.2 Stateful Failover)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are running &lt;G class="gr_ gr_1739 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="1739" data-gr-id="1739"&gt;ospf&lt;/G&gt;&amp;nbsp;on core switches and ASA Firewall outside interfaces Ten0/8 on both firewalls are also configured in &lt;G class="gr_ gr_2129 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2129" data-gr-id="2129"&gt;ospf&lt;/G&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Firewall1 is primary and Firewall2 is the secondary pair in failover.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When Primary firewall is active &lt;G class="gr_ gr_2223 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2223" data-gr-id="2223"&gt;ospf&lt;/G&gt;&amp;nbsp;neighborship goes as well as I can not ping the subinterfaces created under inside interface port-channel&lt;/P&gt;
&lt;P&gt;when I make my secondary firewall as active &lt;G class="gr_ gr_2309 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2309" data-gr-id="2309"&gt;ospf&lt;/G&gt;&amp;nbsp;neighborship comes up and also I'm able to ping subinterfaces created for my inside networks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could be the problem, is it something to do with port-channel configuration or failover configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all in advance for kind response.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Asad.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5585-x-ssp40-failover-problem/m-p/3080723#M135098</guid>
      <dc:creator>Atasawar1</dc:creator>
      <dc:date>2019-03-12T09:26:47Z</dc:date>
    </item>
    <item>
      <title>This is to inform you all if</title>
      <link>https://community.cisco.com/t5/network-security/asa5585-x-ssp40-failover-problem/m-p/3080724#M135099</link>
      <description>&lt;P&gt;This is to inform you all if someone wonders that what happened to above-mentioned problem.&lt;/P&gt;
&lt;P&gt;There are four ports connecting to core switches from firewalls. I created single port-channel for all four interfaces connecting to all four interfaces two each to respective firewalls and I was facing above mentioned problem but as soon as I created two port-channels for each two interfaces connecting to the respective firewall, everything came up and running. And life is good now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 18:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5585-x-ssp40-failover-problem/m-p/3080724#M135099</guid>
      <dc:creator>Atasawar1</dc:creator>
      <dc:date>2017-06-01T18:07:14Z</dc:date>
    </item>
  </channel>
</rss>

