<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you are using the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987920#M144469</link>
    <description>&lt;P&gt;If you are using the FirePOWER (sfr) modules, you should definitely upgrade. You are running the very first version of ASA software that supported them and the very first version of FirePOWER software available on the ASA sfr module as well. There have been numerous upgrades and literally hundreds of bug fixes since those versions.&lt;/P&gt;
&lt;P&gt;If you are not using them, then simply uninstall the modules. It's a simple non-disruptive (to the parent ASA) command. Do it on the standby unit first and then the active unit and it won't even trigger another failover. Your configurations will be lost unless you are using FirePOWER Management Center (previously known as FireSIGHT Management Center or Defense Center). In that case, all policies can be re-applied to the units once have have upgraded the software to a current stable release.&lt;/P&gt;</description>
    <pubDate>Sun, 04 Dec 2016 11:18:51 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-12-04T11:18:51Z</dc:date>
    <item>
      <title>ASA Failover issue with SFR installed.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987913#M144459</link>
      <description>&lt;P&gt;Hello Experts,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I have two ASA 5545-X boxes installed and both the boxes has SFR module installed though the license has been expired and we are going to renew it soon. Both the ASA boxes have multiple contexts and are fail-over pair. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue i am having is the firewall fails over with the below reason. I think the SFR module is having issue and lead the fail-over. Can i remove this module from fail-over configuration or shut down this module. Here is the configuration we have.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Failover reason:-&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Just Active &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active Drain &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Service card in other unit has failed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sh failover&lt;BR /&gt;&lt;/STRONG&gt; This host: Primary - Active&lt;BR /&gt; slot 0: ASA5545 hw/sw rev (1.0/9.2(2)4) status (Up Sys)&lt;BR /&gt; slot 1: SFR5545 hw/sw rev (N/A/5.3.1-152) status (Up/Up)&lt;BR /&gt; Other host: Secondary - Standby Ready&lt;BR /&gt; slot 0: ASA5545 hw/sw rev (1.0/9.2(2)4) status (Up Sys)&lt;BR /&gt; slot 1: SFR5545 hw/sw rev (N/A/5.3.1-155) status (Up/Up)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sh run failover&lt;/STRONG&gt;&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface failover Gi0/1.1&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link statelink GigabitEthernet0/1.2&lt;BR /&gt;failover interface ip failover 192.168.100.1 255.255.255.0 standby 192.168.100.2&lt;BR /&gt;failover interface ip statelink 192.168.101.1 255.255.255.0 standby 192.168.101.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the help.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Pankaj&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987913#M144459</guid>
      <dc:creator>ScarFace P</dc:creator>
      <dc:date>2019-03-12T08:36:48Z</dc:date>
    </item>
    <item>
      <title>no monitor-interface service</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987914#M144460</link>
      <description>&lt;PRE class="prettyprint"&gt;no monitor-interface service-module&lt;/PRE&gt;
&lt;P&gt;should do the trick.&amp;nbsp;Edit: This feature&amp;nbsp;was introduced in version 9.3(1)&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 12:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987914#M144460</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-12-02T12:48:24Z</dc:date>
    </item>
    <item>
      <title>Thank you Iwen for quick</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987915#M144461</link>
      <description>&lt;P&gt;Thank you Iwen for quick response, we have&amp;nbsp;Version 9.2(2)4 so i am not able to run this command. Anything can be done on the existing version.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 13:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987915#M144461</guid>
      <dc:creator>ScarFace P</dc:creator>
      <dc:date>2016-12-02T13:02:05Z</dc:date>
    </item>
    <item>
      <title>Any particular reason that</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987916#M144462</link>
      <description>&lt;P&gt;Any particular reason that you can't or don't want to upgrade your firewall?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 13:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987916#M144462</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-12-02T13:53:32Z</dc:date>
    </item>
    <item>
      <title>There is no particular reason</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987917#M144463</link>
      <description>&lt;P&gt;There is no particular reason, we have planned the&amp;nbsp;upgrade next year but the module is failing frequently almost twice a week. &amp;nbsp;If we shut this module down and remove all the related configuration i.e. policy. Will it still be monitored and the change will be disruptive change.!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 16:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987917#M144463</guid>
      <dc:creator>ScarFace P</dc:creator>
      <dc:date>2016-12-02T16:15:31Z</dc:date>
    </item>
    <item>
      <title>With these problems, I would</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987918#M144464</link>
      <description>&lt;P&gt;With these problems, I would definitely first shutdown and uninstall FP, then upgrade the ASA to a suggested release and last reinstall the module. If that all doesn't help, you likely need to open a TAC-case.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 16:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987918#M144464</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-12-02T16:48:41Z</dc:date>
    </item>
    <item>
      <title>Pankaj ,</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987919#M144466</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Pankaj ,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What version are SFR modules running? You should upgrade to the latest version and see if that will solve the issue. You should be able to do it without any service disruption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nenad&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 21:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987919#M144466</guid>
      <dc:creator>Nenad Stojanovic</dc:creator>
      <dc:date>2016-12-02T21:09:30Z</dc:date>
    </item>
    <item>
      <title>If you are using the</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987920#M144469</link>
      <description>&lt;P&gt;If you are using the FirePOWER (sfr) modules, you should definitely upgrade. You are running the very first version of ASA software that supported them and the very first version of FirePOWER software available on the ASA sfr module as well. There have been numerous upgrades and literally hundreds of bug fixes since those versions.&lt;/P&gt;
&lt;P&gt;If you are not using them, then simply uninstall the modules. It's a simple non-disruptive (to the parent ASA) command. Do it on the standby unit first and then the active unit and it won't even trigger another failover. Your configurations will be lost unless you are using FirePOWER Management Center (previously known as FireSIGHT Management Center or Defense Center). In that case, all policies can be re-applied to the units once have have upgraded the software to a current stable release.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2016 11:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987920#M144469</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-12-04T11:18:51Z</dc:date>
    </item>
    <item>
      <title>Hi Ninad,</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987921#M144473</link>
      <description>&lt;P&gt;Hi Ninad,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;We are using&amp;nbsp;Software version: 5.3.1-152.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Pankaj &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 14:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987921#M144473</guid>
      <dc:creator>ScarFace P</dc:creator>
      <dc:date>2016-12-06T14:40:28Z</dc:date>
    </item>
    <item>
      <title>As Marvin said I would</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987922#M144477</link>
      <description>&lt;P&gt;As Marvin said I would upgrade firepower modules. I ran into couple bugs with old versions. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 14:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987922#M144477</guid>
      <dc:creator>Nenad Stojanovic</dc:creator>
      <dc:date>2016-12-06T14:42:42Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin, yes i agree we</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987923#M144478</link>
      <description>&lt;P&gt;Thanks Marvin, yes i agree we should upgrade the code now&amp;nbsp;and we have in out plan for next year. When you say&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;Your configurations will be lost unless you are using FirePOWER Management Center (previously known as FireSIGHT Management Center or Defense Center)."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;which configuration are you reffering to, only SFR related config i.e. class map and service policy configuration or the firewall configuration...!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 14:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987923#M144478</guid>
      <dc:creator>ScarFace P</dc:creator>
      <dc:date>2016-12-06T14:44:01Z</dc:date>
    </item>
    <item>
      <title>Thank you experts,  Ninad,</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987924#M144480</link>
      <description>&lt;P&gt;Thank you experts, &amp;nbsp;Ninad, Marvin, Iwen for your valuable inputs and help. I think i should keep it shutdown till the next upgrade.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 14:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987924#M144480</guid>
      <dc:creator>ScarFace P</dc:creator>
      <dc:date>2016-12-06T14:47:15Z</dc:date>
    </item>
    <item>
      <title>@pankajm.bisht  ,</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987925#M144481</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[@pankajm.bisht]&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;I was referring only to the FirePOWER policies on the modules themselves. Your base ASA policies would not be affected.&lt;/P&gt;
&lt;P&gt;You would, of course, need to go into the ASA and remove any policy map that includes redirection to the module prior to uninstalling it.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 15:55:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/2987925#M144481</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-12-06T15:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: no monitor-interface service</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/3749427#M144483</link>
      <description>So how do you stop monitoring your service module is versions less than 9.3? I mean Thats a huge feature missing there in all versions when you are dealing with ASA and Service Modules.</description>
      <pubDate>Mon, 19 Nov 2018 17:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/3749427#M144483</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2018-11-19T17:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: no monitor-interface service</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/3749596#M144484</link>
      <description>&lt;P&gt;You can shutdown the sfr module.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.html#56378" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.html#56378&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 21:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue-with-sfr-installed/m-p/3749596#M144484</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-11-19T21:38:47Z</dc:date>
    </item>
  </channel>
</rss>

