<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Failover Failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713771#M187755</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello CSC World!&lt;/P&gt;&lt;P&gt;I just came across an issue where our pair of ASA5525 devices are syncing but showing a "failed" state when issuing the show fail command. Here is the output of the show fail command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Failover On&amp;nbsp;&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: failover GigabitEthernet0/7 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 6 of 216 maximum&lt;BR /&gt;failover replication http&lt;BR /&gt;Version: Ours 9.0(4), Mate 9.0(4)&lt;BR /&gt;Last Failover at: 00:55:14 EDT Mar 25 2015&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This host: Secondary - Active&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 3742577 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5525 hw/sw rev (1.0/9.0(4)) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (66.159.100.4): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (10.5.55.4): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (10.5.10.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz2 (10.5.13.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface testwifi (10.5.51.1): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface guestwifi (10.5.247.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface mgmt (0.0.0.0): Unknown (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: IPS5525 hw/sw rev (N/A/7.1(7)E4) status (Up/Up)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.1(7)E4, Up&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Other host: Primary - Failed&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 8387132 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5525 hw/sw rev (1.0/9.0(4)) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (66.159.100.5): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (10.5.55.5): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (10.5.10.2): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz2 (10.5.13.2): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface testwifi (10.5.51.2): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface guestwifi (10.5.247.2): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface mgmt (0.0.0.0): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: IPS5525 hw/sw rev (N/A/7.1(7)E4) status (Up/Down)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.1(7)E4, Up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I checked to make sure changes are replicating by inputting a remark in the current active firewall and it was replicated without issue to the other. I then looked at the links back to the switches and they are all up and I can ping all the IP addresses associated with the interfaces from the firewalls and switches themselves. In addition, spanning tree is not blocking anything on the uplinks.&lt;/P&gt;&lt;P&gt;The topology is as follows (I can be more detailed, but this should give you a decent idea):&lt;/P&gt;&lt;P&gt;ASA5525-01 ==&amp;gt; Nexus 7K-01 == Nexus 7K-02 &amp;lt;== ASA5525-02&lt;/P&gt;&lt;P&gt;The last failover occurred during a maintenance window when I had to bring down our primary switch, and it seems that it has never failed back.&lt;/P&gt;&lt;P&gt;Any suggestions/input would be appreciated.&lt;/P&gt;&lt;P&gt;Thanks everyone!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:54:09 GMT</pubDate>
    <dc:creator>Nathaniel Wood</dc:creator>
    <dc:date>2019-03-12T05:54:09Z</dc:date>
    <item>
      <title>ASA Failover Failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713771#M187755</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello CSC World!&lt;/P&gt;&lt;P&gt;I just came across an issue where our pair of ASA5525 devices are syncing but showing a "failed" state when issuing the show fail command. Here is the output of the show fail command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Failover On&amp;nbsp;&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: failover GigabitEthernet0/7 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 6 of 216 maximum&lt;BR /&gt;failover replication http&lt;BR /&gt;Version: Ours 9.0(4), Mate 9.0(4)&lt;BR /&gt;Last Failover at: 00:55:14 EDT Mar 25 2015&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This host: Secondary - Active&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 3742577 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5525 hw/sw rev (1.0/9.0(4)) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (66.159.100.4): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (10.5.55.4): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (10.5.10.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz2 (10.5.13.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface testwifi (10.5.51.1): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface guestwifi (10.5.247.1): Normal (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface mgmt (0.0.0.0): Unknown (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: IPS5525 hw/sw rev (N/A/7.1(7)E4) status (Up/Up)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.1(7)E4, Up&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Other host: Primary - Failed&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active time: 8387132 (sec)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 0: ASA5525 hw/sw rev (1.0/9.0(4)) status (Up Sys)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface outside (66.159.100.5): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface inside (10.5.55.5): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz (10.5.10.2): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface dmz2 (10.5.13.2): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface testwifi (10.5.51.2): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface guestwifi (10.5.247.2): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface mgmt (0.0.0.0): No Link (Waiting)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; slot 1: IPS5525 hw/sw rev (N/A/7.1(7)E4) status (Up/Down)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IPS, 7.1(7)E4, Up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I checked to make sure changes are replicating by inputting a remark in the current active firewall and it was replicated without issue to the other. I then looked at the links back to the switches and they are all up and I can ping all the IP addresses associated with the interfaces from the firewalls and switches themselves. In addition, spanning tree is not blocking anything on the uplinks.&lt;/P&gt;&lt;P&gt;The topology is as follows (I can be more detailed, but this should give you a decent idea):&lt;/P&gt;&lt;P&gt;ASA5525-01 ==&amp;gt; Nexus 7K-01 == Nexus 7K-02 &amp;lt;== ASA5525-02&lt;/P&gt;&lt;P&gt;The last failover occurred during a maintenance window when I had to bring down our primary switch, and it seems that it has never failed back.&lt;/P&gt;&lt;P&gt;Any suggestions/input would be appreciated.&lt;/P&gt;&lt;P&gt;Thanks everyone!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713771#M187755</guid>
      <dc:creator>Nathaniel Wood</dc:creator>
      <dc:date>2019-03-12T05:54:09Z</dc:date>
    </item>
    <item>
      <title>The output indicates the IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713772#M187757</link>
      <description>&lt;P&gt;The output indicates the IPS module on your Primary unit is up but its data plane connection is down. It needs to be Up/Up for the unit to be marked as ready.&lt;/P&gt;
&lt;P&gt;Try reloading the IPS module on that unit only:&lt;/P&gt;

&lt;PRE&gt;
sw-module module ips reload&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 May 2015 13:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713772#M187757</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-05-07T13:02:55Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin, Thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713773#M187759</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick response, that has done the trick!&lt;/P&gt;&lt;P&gt;I overlooked the IPS as the issue as all the other interfaces were showing No Link (Waiting) and thought the issue was somewhere on the actual uplinks.&lt;/P&gt;&lt;P&gt;Makes sense that if the data plane is down, it won't do anything &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2015 13:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-failure/m-p/2713773#M187759</guid>
      <dc:creator>Nathaniel Wood</dc:creator>
      <dc:date>2015-05-07T13:25:09Z</dc:date>
    </item>
  </channel>
</rss>

