<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If the pings do not work as in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851474#M153035</link>
    <description>&lt;P&gt;If the pings do not work as Aditaya stated Make sure the interface is active for the failover link.&amp;nbsp; Your config looks fine to me.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2016 16:44:07 GMT</pubDate>
    <dc:creator>jpederson1</dc:creator>
    <dc:date>2016-06-15T16:44:07Z</dc:date>
    <item>
      <title>ASA Failover configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851472#M153033</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have this configuration in 2 ASA firewalls to enable failover, but for some reason its not working.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Primary-ASA# sh run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FOLINK GigabitEthernet2&lt;BR /&gt;failover interface ip FOLINK 112.1.1.1 255.255.255.0 standby 112.1.1.2&lt;BR /&gt;Primary-ASA#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Secondary-ASA# sh run failover&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface FOLINK GigabitEthernet2&lt;BR /&gt;failover interface ip FOLINK 112.1.1.1 255.255.255.0 standby 112.1.1.2&lt;BR /&gt;Secondary-ASA#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But the failover is not able to detect the mate.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Primary-ASA# sh failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: FOLINK GigabitEthernet2 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 0 of 60 maximum&lt;BR /&gt;Version: Ours 8.4(2), Mate Unknown&lt;BR /&gt;Last Failover at: 02:43:18 UTC Jun 15 2016&lt;BR /&gt; &lt;STRONG&gt;This host: Primary - Active&lt;/STRONG&gt;&lt;BR /&gt; Active time: 15501 (sec)&lt;BR /&gt; &lt;STRONG&gt;Other host: Secondary - Not Detected&lt;/STRONG&gt;&lt;BR /&gt; Active time: 0 (sec)&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : Unconfigured.&lt;/P&gt;
&lt;P&gt;Primary-ASA#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Secondary-ASA# sh failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: FOLINK GigabitEthernet2 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 0 of 60 maximum&lt;BR /&gt;Version: Ours 8.4(2), Mate Unknown&lt;BR /&gt;Last Failover at: 02:27:35 UTC Jun 15 2016&lt;BR /&gt; &lt;STRONG&gt;This host: Secondary - Active&lt;/STRONG&gt;&lt;BR /&gt; Active time: 14123 (sec)&lt;BR /&gt; &lt;STRONG&gt;Other host: Primary - Failed&lt;/STRONG&gt;&lt;BR /&gt; Active time: 0 (sec)&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : Unconfigured.&lt;/P&gt;
&lt;P&gt;Secondary-ASA#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can anyone please explain why this is not working?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;CF&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851472#M153033</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2019-03-12T07:53:18Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851473#M153034</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are you able to ping the failover IP's ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 06:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851473#M153034</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-15T06:35:49Z</dc:date>
    </item>
    <item>
      <title>If the pings do not work as</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851474#M153035</link>
      <description>&lt;P&gt;If the pings do not work as Aditaya stated Make sure the interface is active for the failover link.&amp;nbsp; Your config looks fine to me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 16:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851474#M153035</guid>
      <dc:creator>jpederson1</dc:creator>
      <dc:date>2016-06-15T16:44:07Z</dc:date>
    </item>
    <item>
      <title>Don't know if its something</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851475#M153036</link>
      <description>&lt;P&gt;Don't know if its something related to GNS3, but I reapplied the same command it started working.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Version: Ours 8.4(2), Mate 8.4(2)&lt;BR /&gt;Last Failover at: 19:08:37 UTC Jun 15 2016&lt;BR /&gt; This host: Primary - Active&lt;BR /&gt; Active time: 867 (sec)&lt;BR /&gt; Other host: Secondary - Standby Ready&lt;BR /&gt; Active time: 0 (sec)&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 19:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851475#M153036</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-06-15T19:27:51Z</dc:date>
    </item>
    <item>
      <title>I have one more question.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851476#M153037</link>
      <description>&lt;P&gt;I have one more question.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Primary-ASA# sh failover&lt;BR /&gt;Failover On&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: FOLINK GigabitEthernet2 (up)&lt;BR /&gt;&lt;STRONG&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/STRONG&gt;&lt;BR /&gt;Interface Policy 1&lt;/P&gt;
&lt;P&gt;What's unit poll frequency vs interface poll?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 19:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851476#M153037</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-06-15T19:28:51Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851477#M153038</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is a brief explanation:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Failover Poll Times-Contains the fields for defining how often hello messages are sent on the failover link, and, optionally, how long to wait before testing the peer for failure if no hello messages are received.&lt;/P&gt;
&lt;P&gt;Unit Failover-The amount of time between hello messages among units. The range is between 1 and 15 seconds or between 200 and 999 milliseconds.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Unit Hold Time-Sets the time during which a unit must receive a hello message on the failover link, or else the unit begins the testing process for peer failure. The range is between 1and 45 seconds or between 800 and 999 milliseconds. You cannot enter a value that is less than 3 times the &lt;/STRONG&gt;&lt;G class="gr_ gr_28 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="28" data-gr-id="28"&gt;polltime&lt;/G&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Monitored Interfaces-The amount of time between polls among interfaces. The range is between 1and 15 seconds or 500 to 999 milliseconds.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Interface Hold Time-Sets the time during which a data interface must receive a hello message on the data interface, after which the peer is declared failed. Valid values are from 5 to 75 seconds.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Aditya&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please rate helpful posts and mark correct answers.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 00:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851477#M153038</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-16T00:25:40Z</dc:date>
    </item>
    <item>
      <title>Thanks Aditya for the the</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851478#M153039</link>
      <description>&lt;P&gt;Thanks Aditya for the the detailed explanation.&lt;/P&gt;
&lt;P&gt;So unit polling is done by each ASA to make sure the peer ASA is available.&lt;/P&gt;
&lt;P&gt;And the interface poll is done by each ASA to make sure that all&amp;nbsp;monitored interface in both the ASA are fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If the hold time expires for any of these polls, then that interface is set in test mode and a 4 step test is conducted in that interface. If the unit poll is failing the failover link between ASAs will be tested. If the interface poll expires, then that specific interface will be tested.&lt;/P&gt;
&lt;P&gt;Am I right?&lt;/P&gt;
&lt;P&gt;CF&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 02:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851478#M153039</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-06-16T02:41:05Z</dc:date>
    </item>
    <item>
      <title>Hi&lt;</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851479#M153040</link>
      <description>&lt;P&gt;Hi&amp;lt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_19 gr-alert gr_gramm gr_run_anim Punctuation only-ins replaceWithoutSep" id="19" data-gr-id="19"&gt;Yes&lt;/G&gt; you are correct.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can go through this link as well:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/77809-pixfailover.html#tri&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 02:47:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851479#M153040</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-16T02:47:14Z</dc:date>
    </item>
    <item>
      <title>Awesome!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851480#M153041</link>
      <description>&lt;P&gt;Awesome!!!&lt;/P&gt;
&lt;P&gt;One last question.. Should all the 4 tests pass for an interface to return to an active status. Or even passing 1 out of that 4 will put the interface back in active status?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;CF&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 02:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851480#M153041</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-06-16T02:59:37Z</dc:date>
    </item>
    <item>
      <title>All the tests should be</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851481#M153042</link>
      <description>&lt;P&gt;All the tests should be passed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check this link:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/document/13076/understanding-how-interface-testing-works-pix-failover&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 03:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-configuration/m-p/2851481#M153042</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-16T03:13:01Z</dc:date>
    </item>
  </channel>
</rss>

