<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active/Standby Main ISP failover FAILED in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-standby-main-isp-failover-failed/m-p/3683786#M14629</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like your help regarding my issue on my Active/Standby configuration on my ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my topology and configuration below to better understand:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="active_standby.PNG" style="width: 621px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16369i7F4B39F1FDF544F9/image-dimensions/621x449?v=v2" width="621" height="449" role="button" title="active_standby.PNG" alt="active_standby.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ACTIVE ASA CONFIG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER gi0/3&lt;BR /&gt;failover interface ip FAILOVER 10.10.10.1 255.255.255.0 standby 10.10.10.2&lt;BR /&gt;failover key test.com&lt;BR /&gt;failover&lt;/P&gt;
&lt;P&gt;failover link STATE gi0/4&lt;BR /&gt;failover interface IP STATE 20.20.20.1 255.255.255.0 standby 20.20.20.2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;interface g0/0&lt;BR /&gt;channel-group 1 mode on&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface g0/1&lt;BR /&gt;nameif ISP1&lt;BR /&gt;securit-level 0&lt;BR /&gt;ip address 1.1.1.2 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface g0/2&lt;BR /&gt;nameif ISP2&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 2.2.2.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface port-channel 10&lt;BR /&gt;max lacp-bundle 8&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.0.1 255.255.255.0 standby 192.168.0.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;route ISP1 0.0.0.0 0.0.0.0 1.1.1.1 1&lt;BR /&gt;route ISP2 0.0.0.0 0.0.0.0 2.2.2.2 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;STANDBY ASA CONFIG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface FAILOVER gi0/3&lt;BR /&gt;failover interface ip FAILOVER 10.10.10.1 255.255.255.0 standby 10.10.10.2&lt;BR /&gt;failover key test.com&lt;BR /&gt;failover&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is when I shut down my INSIDE interface going to the STANDBY ASA and my OUTSIDE LINK going to the ISP 1 from my ACTIVE ASA, my inside link has no longer access to the internet. When I am in the L3 Switch and I tried to ping the ASA IP (192.168.0.1) I am no longer able to ping it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I expect that since the main ISP which is ISP 1 on STANDBY ASA is still active, the traffic should go there. However, it does not. it does not even go to the backup ISP which is ISP 2 on my ACTIVE ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if I do it vice versa (shutdown the INSIDE link going to ACTIVE ASA and OUTSIDE link from my STANDBY ASA going to ISP 1) it works. The traffic is still passing thru&amp;nbsp;ISP 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="active_standby_fail.PNG" style="width: 804px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16370i83953A54A5539B01/image-size/large?v=v2&amp;amp;px=999" role="button" title="active_standby_fail.PNG" alt="active_standby_fail.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Thanks in advance!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kyle&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:04:19 GMT</pubDate>
    <dc:creator>KyleHB</dc:creator>
    <dc:date>2020-02-21T16:04:19Z</dc:date>
    <item>
      <title>Active/Standby Main ISP failover FAILED</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-main-isp-failover-failed/m-p/3683786#M14629</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like your help regarding my issue on my Active/Standby configuration on my ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my topology and configuration below to better understand:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="active_standby.PNG" style="width: 621px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16369i7F4B39F1FDF544F9/image-dimensions/621x449?v=v2" width="621" height="449" role="button" title="active_standby.PNG" alt="active_standby.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ACTIVE ASA CONFIG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER gi0/3&lt;BR /&gt;failover interface ip FAILOVER 10.10.10.1 255.255.255.0 standby 10.10.10.2&lt;BR /&gt;failover key test.com&lt;BR /&gt;failover&lt;/P&gt;
&lt;P&gt;failover link STATE gi0/4&lt;BR /&gt;failover interface IP STATE 20.20.20.1 255.255.255.0 standby 20.20.20.2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;interface g0/0&lt;BR /&gt;channel-group 1 mode on&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface g0/1&lt;BR /&gt;nameif ISP1&lt;BR /&gt;securit-level 0&lt;BR /&gt;ip address 1.1.1.2 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface g0/2&lt;BR /&gt;nameif ISP2&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 2.2.2.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface port-channel 10&lt;BR /&gt;max lacp-bundle 8&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.0.1 255.255.255.0 standby 192.168.0.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;route ISP1 0.0.0.0 0.0.0.0 1.1.1.1 1&lt;BR /&gt;route ISP2 0.0.0.0 0.0.0.0 2.2.2.2 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;STANDBY ASA CONFIG&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface FAILOVER gi0/3&lt;BR /&gt;failover interface ip FAILOVER 10.10.10.1 255.255.255.0 standby 10.10.10.2&lt;BR /&gt;failover key test.com&lt;BR /&gt;failover&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is when I shut down my INSIDE interface going to the STANDBY ASA and my OUTSIDE LINK going to the ISP 1 from my ACTIVE ASA, my inside link has no longer access to the internet. When I am in the L3 Switch and I tried to ping the ASA IP (192.168.0.1) I am no longer able to ping it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I expect that since the main ISP which is ISP 1 on STANDBY ASA is still active, the traffic should go there. However, it does not. it does not even go to the backup ISP which is ISP 2 on my ACTIVE ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if I do it vice versa (shutdown the INSIDE link going to ACTIVE ASA and OUTSIDE link from my STANDBY ASA going to ISP 1) it works. The traffic is still passing thru&amp;nbsp;ISP 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="active_standby_fail.PNG" style="width: 804px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16370i83953A54A5539B01/image-size/large?v=v2&amp;amp;px=999" role="button" title="active_standby_fail.PNG" alt="active_standby_fail.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Thanks in advance!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kyle&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-main-isp-failover-failed/m-p/3683786#M14629</guid>
      <dc:creator>KyleHB</dc:creator>
      <dc:date>2020-02-21T16:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Standby Main ISP failover FAILED</title>
      <link>https://community.cisco.com/t5/network-security/active-standby-main-isp-failover-failed/m-p/3683809#M14631</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on my understanding, ISP 1 is your primary isp and ISP 2 your secondary.&lt;/P&gt;
&lt;P&gt;First of all, i would configure tracking on your primary default route which will trigger the secondary default route being installed in your asa RIB if your tracking is down. You can use what ever ip on the internet like Google dns.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then ensure which interface you're monitoring and if you configured monitor interface-policy feature. You don't want to failover the secondary unit if only isp1 goes&amp;nbsp;down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, on your scenario, can you confirm which asa is the active one when shutting down isp1?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If a failover occurs when isp 1 is down and you shut the inside interface on asa 2, traffic won't go through asa 1 to come back to asa 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 03:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-standby-main-isp-failover-failed/m-p/3683809#M14631</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-08-08T03:10:54Z</dc:date>
    </item>
  </channel>
</rss>

