<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please check first if you are in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933649#M150114</link>
    <description>&lt;P&gt;Please check first if you are able to ping Management interface IP of each other. If no then check cable connectivity between this two. If still see the issue you can reboot the standby unit but make sure yous should do this in non production hours because it has risk of both unit become Active at a time.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Sep 2016 11:59:07 GMT</pubDate>
    <dc:creator>Pawan Raut</dc:creator>
    <dc:date>2016-09-12T11:59:07Z</dc:date>
    <item>
      <title>Cisco ASA standby failed - pls help</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933645#M150110</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In my ASA 8.4(7)30 HA setup, i do see standby failed when i run show failover in Primary FW (Active) as given below.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Primary - Active FW&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;# show failover&lt;/P&gt;
&lt;P&gt;This host: Primary - Active &lt;BR /&gt;Other host: Secondary - &lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Failed &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Secondary - Standby FW&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;# show failover&lt;/P&gt;
&lt;P&gt;This host: Secondary - Standby Ready &lt;BR /&gt;Other host: Primary - Active&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have executed below debugs in the standby FW, and got few logs.&lt;/P&gt;
&lt;P&gt;debug fover verify&lt;BR /&gt;debug fover fail&lt;BR /&gt;debug fover sync&lt;/P&gt;
&lt;P&gt;ASA failover HA TRANS: received out of sequence message&lt;BR /&gt;fover_ip: HA TRANS: &lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;received out of sequence message&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;, seq - ba4514b, expect - ba45144&lt;BR /&gt;fover_ip: HA TRANS: send aggressive ACK&lt;BR /&gt;fover_ip: HA TRANS: received out of sequence message, seq - ba45147, expect - ba45144&lt;BR /&gt;fover_ip: HA TRANS: send aggressive ACK&lt;BR /&gt;fover_ip: HA TRANS: received out of sequence message, seq - ba45150, expect - ba45144&lt;BR /&gt;fover_ip: HA TRANS: send aggressive ACK&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;%ASA-6-720024: (VPN-Secondary) HA status callback: &lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Control channel is down&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;.&lt;BR /&gt;%ASA-6-721002: (WebVPN-Secondary) HA status change: event HA_STATUS_PEER_CTL_COMM, my state Standby Ready, peer state Active.&lt;BR /&gt;%ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=401,op=1,my=Standby Ready,peer=Active.&lt;BR /&gt;%ASA-6-720024: (VPN-Secondary) HA status callback: &lt;EM&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Control channel is up&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/EM&gt;.&lt;BR /&gt;%ASA-6-721002: (WebVPN-Secondary) HA status change: event HA_STATUS_PEER_CTL_COMM, my state Standby Ready, peer state Active.&lt;BR /&gt;%ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=411,op=52,my=Standby Ready,peer=Active.&lt;BR /&gt;%ASA-6-721002: (WebVPN-Secondary) HA status change: event HA_STATUS_CLIENT_NEGOTIATED_VERSION, my state Standby Ready, peer state Active.&lt;BR /&gt;%ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=401,op=0,my=Standby Ready,peer=Active.&lt;BR /&gt;%ASA-6-720024: (VPN-Secondary) HA status callback: Control channel is down.&lt;/P&gt;
&lt;P&gt;These messages floods in the show logging..&lt;/P&gt;
&lt;P&gt;Can someone assist me..&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:15:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933645#M150110</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2019-03-12T08:15:10Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933646#M150111</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Could you kindly please, check the status of the interface that works as the failover link, and attach a show failover and show failover state.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 20:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933646#M150111</guid>
      <dc:creator>Kornelia Gutierrez</dc:creator>
      <dc:date>2016-09-08T20:09:05Z</dc:date>
    </item>
    <item>
      <title>Hi Kornelia Gutierrez,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933647#M150112</link>
      <description>Hi Kornelia Gutierrez, 

Please find the attached logs from both the firewalls.</description>
      <pubDate>Fri, 09 Sep 2016 11:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933647#M150112</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2016-09-09T11:02:03Z</dc:date>
    </item>
    <item>
      <title>pls find the attached show</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933648#M150113</link>
      <description>&lt;P&gt;pls find the attached show failover logs from both the firewall, i think i need to reboot the secondary standby firewall - what do you say ?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 11:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933648#M150113</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2016-09-12T11:44:35Z</dc:date>
    </item>
    <item>
      <title>Please check first if you are</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933649#M150114</link>
      <description>&lt;P&gt;Please check first if you are able to ping Management interface IP of each other. If no then check cable connectivity between this two. If still see the issue you can reboot the standby unit but make sure yous should do this in non production hours because it has risk of both unit become Active at a time.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 11:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933649#M150114</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2016-09-12T11:59:07Z</dc:date>
    </item>
    <item>
      <title>Hi, </title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933650#M150115</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case of reboot a standby Unit i disconnect all interface cables and connect only failover interface cable.&lt;/P&gt;
&lt;P&gt;Then wait for negotiate failover active and passive then connect all other cables again&lt;/P&gt;
&lt;P&gt;In this case there is no risk that both units become active&lt;/P&gt;
&lt;P&gt;Regards Marco&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 13:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933650#M150115</guid>
      <dc:creator>Marco Soeder-Schuettler</dc:creator>
      <dc:date>2016-09-12T13:09:21Z</dc:date>
    </item>
    <item>
      <title>Ok Marco, By seeing the debug</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933651#M150116</link>
      <description>&lt;P&gt;Ok Marco, By seeing the debug logs and show failover outputs of both Fws, I seriously suspect issue with standby fw only, so I will go ahead remove all the cables except Mgmt0/0, reboot the Standby fw, then i will connect cables one by one.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 13:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933651#M150116</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2016-09-12T13:15:47Z</dc:date>
    </item>
    <item>
      <title>Yes, so you can do ;-)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933652#M150119</link>
      <description>&lt;P&gt;Yes, so you can do &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Make sure that active / passive negotiation is already done.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 13:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-standby-failed-pls-help/m-p/2933652#M150119</guid>
      <dc:creator>Marco Soeder-Schuettler</dc:creator>
      <dc:date>2016-09-12T13:34:03Z</dc:date>
    </item>
  </channel>
</rss>

