<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Link:- http://www.cisco.com/c in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/4010502#M202227</link>
    <description>&lt;P&gt;Hi Rajesh,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a catch here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.If you only have standby ip address configured for failover interface and no standby ip address for any other data interface,as soon as the fail over link goes down,both units will be active and it would be SPLIT BRAIN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.In case you have standby ip addresses configured for all other data interfaces as well apart from failover link,the failover would not happen and the primary unit would still retain the active role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2020 14:28:39 GMT</pubDate>
    <dc:creator>vaishar3</dc:creator>
    <dc:date>2020-01-13T14:28:39Z</dc:date>
    <item>
      <title>cisco asa HA failover link</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588540#M202222</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have one interface Eth2 for failover link (statless) and another interface Eth3 stateful failover.&lt;/P&gt;&lt;P&gt;If I remove the failover link Eth2 OR stateful lin Eth3 from Active firewall, will it failover to Standby ?&lt;/P&gt;&lt;P&gt;From the cisco document, i read that, failover will not happpen if failover messages are coming from other interfaces..&lt;/P&gt;&lt;P&gt;Is is&amp;nbsp;true ?? pls confirm.&lt;/P&gt;&lt;P&gt;Have you seen situations, where failover link causes failover to happen ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:13:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588540#M202222</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2019-03-12T05:13:59Z</dc:date>
    </item>
    <item>
      <title>In this situation, failover</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588541#M202223</link>
      <description>&lt;P&gt;In this situation, failover should not happen because the standby ASA is not connected to the network in a better way than the active ASA. But: If the failover link fails, you could end up in split-brain situations where both ASAs get active. Thats the reason this link is sometimes configured as redundant interfaces to make this important link more reliable.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2014 14:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588541#M202223</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-12-15T14:50:52Z</dc:date>
    </item>
    <item>
      <title>Link:- http://www.cisco.com/c</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588542#M202224</link>
      <description>&lt;DIV style="margin-left:.38in;"&gt;Link:-&lt;/DIV&gt;&lt;DIV style="margin-left:.38in;"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="margin-left:.38in;"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/ha_overview.html&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="margin-left:.38in;"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="margin-left:.38in;"&gt;The ASA determines the health of the other unit by monitoring the failover link. When a unit does not receive 3 consecutive hello messages on the failover link, the unit sends interface hello messages on each interface, including the failover interface, to validate whether or not the peer interface is responsive. The action that the ASA takes depends upon the response from the other unit. See the following possible actions:&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left:.44in;"&gt;--&amp;nbsp; If the ASA receives a response on the failover interface, then it does not fail over.&lt;/P&gt;&lt;P style="margin-left:.44in;"&gt;-- If the ASA does not receive a response on the failover link, but it does receive a response on another &amp;nbsp;&amp;nbsp;&amp;nbsp;interface, then the unit does not failover. The failover link is marked as failed. You should restore the failover link as soon as possible because the unit cannot fail over to the standby while the failover link is down.&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left:.44in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left:.44in;"&gt;This says that, even if the failover link goes down, the failover will not happen because the failover messages can be received on the other interfaces like inside and outside.&lt;/P&gt;&lt;P style="margin-left:.44in;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-left:.44in;"&gt;Can you please clarify on this...With Gns3, both are becoming Active, but as per Cisco, it should not.!!!!!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2014 17:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588542#M202224</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2014-12-15T17:31:22Z</dc:date>
    </item>
    <item>
      <title>Please mark this threas as</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588543#M202225</link>
      <description>&lt;P&gt;Please mark this threas as resolved.&lt;/P&gt;&lt;P&gt;Here is the explanation for my doubt..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" style="width: 80%" width="80%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="5"&gt;&lt;P align="center"&gt;Failover Behavior&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;Failure Event &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;Policy &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;Active Action &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;Standby Action &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;Notes &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Failover link failed during operation&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;No failover&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;You should restore the failover link as soon as possible because the unit cannot fail over to the standby unit while the failover link is down.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Failover link failed at &lt;STRONG&gt;startup&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;No failover&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Become active&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;If the failover link is down at startup, both units become active.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Stateful Failover link failed&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;No failover&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;No action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;No action&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;State information becomes out of date, and sessions are terminated if a failover occurs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 16 Dec 2014 06:40:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588543#M202225</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2014-12-16T06:40:48Z</dc:date>
    </item>
    <item>
      <title>Hi karsten,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588544#M202226</link>
      <description>&lt;P&gt;Hi karsten,&lt;/P&gt;
&lt;P&gt;One question so if failover link fails it will not trigger failover and both asa will go in active active state. If this happen then what will be behaviour of asa? Connection will intrupt?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 05:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/2588544#M202226</guid>
      <dc:creator>Pranav Gade</dc:creator>
      <dc:date>2015-11-04T05:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Link:- http://www.cisco.com/c</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/4010502#M202227</link>
      <description>&lt;P&gt;Hi Rajesh,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a catch here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.If you only have standby ip address configured for failover interface and no standby ip address for any other data interface,as soon as the fail over link goes down,both units will be active and it would be SPLIT BRAIN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.In case you have standby ip addresses configured for all other data interfaces as well apart from failover link,the failover would not happen and the primary unit would still retain the active role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 14:28:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ha-failover-link/m-p/4010502#M202227</guid>
      <dc:creator>vaishar3</dc:creator>
      <dc:date>2020-01-13T14:28:39Z</dc:date>
    </item>
  </channel>
</rss>

