<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835128#M174480</link>
    <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you share output of show blocks?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2015 06:06:50 GMT</pubDate>
    <dc:creator>Rishabh Seth</dc:creator>
    <dc:date>2015-11-30T06:06:50Z</dc:date>
    <item>
      <title>Failover issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835126#M174478</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am hoping someone can help me with this issue I am having. On Friday I noticed I lost the ability to telnet and ssh to my Cisco box which is a 5545, ASA version 9.1(1) and ASDM version 7.3(1).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I read it could be a bug and I tried to remove the telnet and SSH commands and reissue them, but it still just times out and it worked perfectly before.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When I logged on I saw the &lt;STRONG&gt;failover state&lt;/STRONG&gt; had the secondary firewall as the &lt;STRONG&gt;active&lt;/STRONG&gt;. So I thought I would reload the &lt;STRONG&gt;standby Primary&lt;/STRONG&gt;&amp;nbsp;from the ASDM to see if that would force the synching of commands across. Yet now the failover state is showing the &lt;STRONG&gt;primary as sync config&lt;/STRONG&gt; instead of standby.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the commands from the standby active I am logged onto:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Result of the command: "show failover"&lt;/P&gt;
&lt;P&gt;Failover On &lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: FAILOVER GigabitEthernet0/3 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 4 of 316 maximum&lt;BR /&gt;Version: Ours 9.1(1), Mate 9.1(1)&lt;BR /&gt;Last Failover at: 15:59:36 GMT/BDT May 17 2015&lt;BR /&gt; This host: Secondary - Active &lt;BR /&gt; Active time: 16853397 (sec)&lt;BR /&gt; slot 0: ASA5545 hw/sw rev (1.0/9.1(1)) status (Up Sys)&lt;BR /&gt; Interface Private (10.2.1.4): Unknown (Waiting)&lt;BR /&gt; Interface DMZ (10.99.14.1): Unknown (Waiting)&lt;BR /&gt; Interface Public (193.63.212.2): Unknown (Waiting)&lt;BR /&gt; Interface management (192.168.1.1): No Link (Waiting)&lt;BR /&gt; Other host: Primary - Sync Config &lt;BR /&gt; Active time: 0 (sec)&lt;BR /&gt; slot 0: ASA5545 hw/sw rev (1.0/9.1(1)) status (Up Sys)&lt;BR /&gt; Interface Private (0.0.0.0): Unknown (Waiting)&lt;BR /&gt; Interface DMZ (0.0.0.0): Unknown (Waiting)&lt;BR /&gt; Interface Public (0.0.0.0): Unknown (Waiting)&lt;BR /&gt; Interface management (0.0.0.0): Unknown (Waiting)&lt;/P&gt;
&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt; Link : Unconfigured.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;__________________&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Result of the command: "show failover state"&lt;/P&gt;
&lt;P&gt;State Last Failure Reason Date/Time&lt;BR /&gt;This host - Secondary&lt;BR /&gt; Active Ifc Failure 15:03:13 GMT/BDT May 17 2015&lt;BR /&gt;Other host - Primary&lt;BR /&gt; Sync Config Comm Failure 14:01:09 GMT/BST Nov 28 2015&lt;/P&gt;
&lt;P&gt;====Configuration State===&lt;BR /&gt; Config Syncing&lt;BR /&gt; Sync Done - STANDBY&lt;BR /&gt;====Communication State===&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;____________________&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Result of the command: "show failover history"&lt;/P&gt;
&lt;P&gt;==========================================================================&lt;BR /&gt;From State To State Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;15:26:19 GMT/BDT May 17 2015&lt;BR /&gt;Just Active Active Drain HELLO not heard from mate&lt;/P&gt;
&lt;P&gt;15:26:19 GMT/BDT May 17 2015&lt;BR /&gt;Active Drain Active Applying Config HELLO not heard from mate&lt;/P&gt;
&lt;P&gt;15:26:19 GMT/BDT May 17 2015&lt;BR /&gt;Active Applying Config Active Config Applied HELLO not heard from mate&lt;/P&gt;
&lt;P&gt;15:26:19 GMT/BDT May 17 2015&lt;BR /&gt;Active Config Applied Active HELLO not heard from mate&lt;/P&gt;
&lt;P&gt;15:34:30 GMT/BDT May 17 2015&lt;BR /&gt;Active Cold Standby Failover state check&lt;/P&gt;
&lt;P&gt;15:34:32 GMT/BDT May 17 2015&lt;BR /&gt;Cold Standby Sync Config Failover state check&lt;/P&gt;
&lt;P&gt;15:34:42 GMT/BDT May 17 2015&lt;BR /&gt;Sync Config Sync File System Failover state check&lt;/P&gt;
&lt;P&gt;15:34:42 GMT/BDT May 17 2015&lt;BR /&gt;Sync File System Bulk Sync Failover state check&lt;/P&gt;
&lt;P&gt;15:34:42 GMT/BDT May 17 2015&lt;BR /&gt;Bulk Sync Standby Ready Failover state check&lt;/P&gt;
&lt;P&gt;15:45:47 GMT/BDT May 17 2015&lt;BR /&gt;Standby Ready Just Active Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:45:47 GMT/BDT May 17 2015&lt;BR /&gt;Just Active Active Drain Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:45:47 GMT/BDT May 17 2015&lt;BR /&gt;Active Drain Active Applying Config Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:45:47 GMT/BDT May 17 2015&lt;BR /&gt;Active Applying Config Active Config Applied Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:45:47 GMT/BDT May 17 2015&lt;BR /&gt;Active Config Applied Active Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:57:08 GMT/BDT May 17 2015&lt;BR /&gt;Active Standby Ready Set by the config command&lt;/P&gt;
&lt;P&gt;15:59:36 GMT/BDT May 17 2015&lt;BR /&gt;Standby Ready Just Active Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:59:36 GMT/BDT May 17 2015&lt;BR /&gt;Just Active Active Drain Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:59:36 GMT/BDT May 17 2015&lt;BR /&gt;Active Drain Active Applying Config Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:59:36 GMT/BDT May 17 2015&lt;BR /&gt;Active Applying Config Active Config Applied Other unit wants me Active&lt;/P&gt;
&lt;P&gt;15:59:36 GMT/BDT May 17 2015&lt;BR /&gt;Active Config Applied Active Other unit wants me Active&lt;/P&gt;
&lt;P&gt;==========================================================================&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now I still have the original issue where I can't telnet or ssh and I am now worried why the failover is stuck in &lt;STRONG&gt;sync config&lt;/STRONG&gt;. Does this mean it is broken or still working?&amp;nbsp;Can I issue a &lt;STRONG&gt;no failover active&lt;/STRONG&gt; on the current primary secondary&amp;nbsp;unit to make the other host the &lt;STRONG&gt;primary&lt;/STRONG&gt; which it should be and will that solve the issue? There must be no downtime from both units being down without prior approval, so I can't just restart them both.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks in advance,&lt;/P&gt;
&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835126#M174478</guid>
      <dc:creator>Mark Cavendish</dc:creator>
      <dc:date>2019-03-12T06:57:38Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835127#M174479</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;From the description it looks like ASA stuck in sync state. In this state, &amp;nbsp;you can not perform failover,'failover write-standby', ' no failover active', 'no failover' these will not work. It would throw an error saying failover is in sync transition state.&lt;/P&gt;
&lt;P&gt;From my experience so far, reloading the 'active' device resolves the issues always. Sometime it takes a lot time if the configuration is big and comes back normally after sometime.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If it is still in sync configuration state then go for a maintenace window and reload the active device. It is possible that this might be the issue why you are not able to access the ASA boxes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remeber to rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 05:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835127#M174479</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-30T05:27:59Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835128#M174480</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you share output of show blocks?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 06:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835128#M174480</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-30T06:06:50Z</dc:date>
    </item>
    <item>
      <title>Thanks both. I guessed a</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835129#M174481</link>
      <description>&lt;P&gt;Thanks both. I guessed&amp;nbsp;a reload would probably be the only thing to fix this after much more googling and issued a reload noconfirm from the ASDM command line interface but it didn't take the command for some reason. I now cannot reload until this coming w/e where I hope to be onsite to schedule a maintenance window and fingers crossed it solves the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I make any changes on the active this week (which won't get sent properly to the secondary), will they sync properly after rebooting the active or is there anything else I should do?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is the result of the sh block command Rishabh:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Result of the command: "sh blocks"&lt;/P&gt;
&lt;P&gt;SIZE MAX LOW CNT&lt;BR /&gt; 0 4200 4188 4200&lt;BR /&gt; 4 500 499 499&lt;BR /&gt; 80 3504 3429 3504&lt;BR /&gt; 256 3224 3137 3218&lt;BR /&gt; 1550 13874 13673 13861&lt;BR /&gt; 2048 2100 2092 2100&lt;BR /&gt; 2560 3732 3729 3732&lt;BR /&gt; 4096 100 99 100&lt;BR /&gt; 8192 100 99 100&lt;BR /&gt; 9344 100 100 100&lt;BR /&gt; 16384 182 182 182&lt;BR /&gt; 65536 16 16 16&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 09:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835129#M174481</guid>
      <dc:creator>Mark Cavendish</dc:creator>
      <dc:date>2015-11-30T09:20:13Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835130#M174482</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So the reload did not work after running it from ASDM. Can you check the output of show reload for the firewall which was supposed to be reloaded.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 09:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835130#M174482</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-30T09:24:08Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835131#M174483</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;Blocks looks fine. Therefore,&amp;nbsp;there is no block depletion which could have cause loss of ssh or telnet access to ASA.&lt;/P&gt;
&lt;P&gt;Reload of current Active ASA&amp;nbsp;awould be enough. After the reload they must come up fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 11:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835131#M174483</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-30T11:13:02Z</dc:date>
    </item>
    <item>
      <title>Hi all</title>
      <link>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835132#M174484</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just to confirm a reload after the w/e sorted both issues with the failover and telnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks for all your advice again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 08:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-issue/m-p/2835132#M174484</guid>
      <dc:creator>Mark Cavendish</dc:creator>
      <dc:date>2015-12-07T08:53:51Z</dc:date>
    </item>
  </channel>
</rss>

