<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When you power on the primary in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554924#M236830</link>
    <description>&lt;P&gt;When you power on the primary does the secondary also remain as Active or does it switch to standby?&lt;/P&gt;&lt;P&gt;From primary, after power on, are you able to ping the internet? 4.2.2.2 for example?&lt;/P&gt;&lt;P&gt;Your configuration looks fine. This might be a bug.&amp;nbsp; Have you considered upgrading the ASA version?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Sat, 05 Jul 2014 08:41:21 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-07-05T08:41:21Z</dc:date>
    <item>
      <title>Cisco ASA Active standby failover problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554923#M236829</link>
      <description>&lt;P&gt;We have configured&amp;nbsp;ASA Active standby failover with ASA5505 . When primary unit power off, secondary unit became active. when primary unit power on, then primary unit is becoming active again. i think for active standby setup there is no preemption. The real issue is when primary ASA became active after power on all the external connectivity getting down. Please see the below config,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA01# show run&lt;/P&gt;&lt;P&gt;ASA01# show running-config&amp;nbsp;&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.2(5)&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;hostname ASA01&lt;BR /&gt;enable password PVSASRJovmamnVkD encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;name 192.168.1.1 MPLS_Router description MPLS_Router&amp;nbsp;&lt;BR /&gt;name 192.168.2.1 SCADA_Router description SCADA_Router&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.3.8 255.255.255.0 standby 192.168.3.9&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 192.168.1.8 255.255.255.0 standby 192.168.1.9&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt;&amp;nbsp;description LAN Failover Interface&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;BR /&gt;clock timezone AST 3&lt;BR /&gt;access-list inside_access_in extended permit icmp any any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit ip any any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit ip any host MPLS_Router&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit icmp any any&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit ip any any&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit ip any 192.168.2.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER Vlan3&lt;BR /&gt;failover key *****&lt;BR /&gt;failover interface ip FAILOVER 10.1.1.1 255.255.255.0 standby 10.1.1.2&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;!&lt;BR /&gt;route-map Route_Out permit 1&lt;BR /&gt;&amp;nbsp;match ip address inside_access_in outside_access_in&lt;BR /&gt;&amp;nbsp;match interface inside&lt;BR /&gt;!&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 MPLS_Router 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;http 192.168.2.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http authentication-certificate inside&lt;BR /&gt;http authentication-certificate outside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet 192.168.2.0 255.255.255.0 inside&lt;BR /&gt;telnet 192.168.1.0 255.255.255.0 outside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;username admin password eY/fQXw7Ure8Qrz7 encrypted&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:1a8e46a787aa78502ffd881ab62d1c31&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554923#M236829</guid>
      <dc:creator>shabeer sulaiman</dc:creator>
      <dc:date>2019-03-12T04:25:38Z</dc:date>
    </item>
    <item>
      <title>When you power on the primary</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554924#M236830</link>
      <description>&lt;P&gt;When you power on the primary does the secondary also remain as Active or does it switch to standby?&lt;/P&gt;&lt;P&gt;From primary, after power on, are you able to ping the internet? 4.2.2.2 for example?&lt;/P&gt;&lt;P&gt;Your configuration looks fine. This might be a bug.&amp;nbsp; Have you considered upgrading the ASA version?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jul 2014 08:41:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554924#M236830</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-07-05T08:41:21Z</dc:date>
    </item>
    <item>
      <title>Thank you for your quick</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554925#M236831</link>
      <description>&lt;P&gt;Thank you for your quick response.&lt;/P&gt;&lt;P&gt;When we power on primary unit, secondary unit moving to standby.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We cannot ping to our internet router. The strange things which we noticed that we can ping to 192.168.3.9(Standby ASA), we cannot ping to 192.168.3.8(Primary ASA) when primary ASA power on and become active.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jul 2014 09:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554925#M236831</guid>
      <dc:creator>shabeer sulaiman</dc:creator>
      <dc:date>2014-07-05T09:36:19Z</dc:date>
    </item>
    <item>
      <title>I suggest removing the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554926#M236832</link>
      <description>&lt;P&gt;I suggest removing the failover configuration on both units and then re-add them, and then test.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Primary&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;failover lan interface FAILOVER Vlan3&lt;BR /&gt;failover interface ip FAILOVER 10.1.1.1 255.255.255.0 standby 10.1.1.2&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover key KEY&lt;BR /&gt;failover&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Secondary&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;failover lan interface FAILOVER Vlan3&lt;BR /&gt;failover interface ip FAILOVER 10.1.1.1 255.255.255.0 standby 10.1.1.2&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover key KEY&lt;BR /&gt;failover&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jul 2014 13:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-active-standby-failover-problem/m-p/2554926#M236832</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-07-05T13:28:52Z</dc:date>
    </item>
  </channel>
</rss>

