<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Are the interfaces excluded in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442727#M238703</link>
    <description>&lt;P&gt;Are the interfaces excluded from failover monitoring in the config? ("no monitor-interface dmz")&lt;/P&gt;</description>
    <pubDate>Wed, 07 May 2014 15:45:47 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-05-07T15:45:47Z</dc:date>
    <item>
      <title>ASA 8.4(4) failover issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442724#M238700</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having a strange behaviour in an ASA cluster running 8.4(4) regarding failover feature, from the Active node standpoint if I issue a "show failover" I have the following result&lt;/P&gt;&lt;P&gt;------------------ show failover ------------------&lt;/P&gt;&lt;P&gt;Failover On&amp;nbsp;&lt;BR /&gt;Failover unit Primary&lt;BR /&gt;Failover LAN Interface: dmz_failover GigabitEthernet0/2 (up)&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 3 seconds&lt;BR /&gt;Interface Poll frequency 1 seconds, holdtime 5 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 2 of 160 maximum&lt;BR /&gt;failover replication http&lt;BR /&gt;Version: Ours 8.4(4), Mate 8.4(4)&lt;BR /&gt;Last Failover at: 13:12:39 UTC May 6 2014&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;This host: Primary - Active&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Active time: 1247 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;slot 0: ASA5520 hw/sw rev (2.0/8.4(4)) status (Up Sys)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface internetwork.wan (192.168.236.99): Normal (Monitored)&lt;BR /&gt;&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface A.dmz (192.168.236.33): Link Down (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface B.dmz (192.168.236.1): Link Down (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface C.dmz (192.168.236.65): Link Down (Not-Monitored)&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface xerox.network (192.168.1.20): Normal (Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface management (0.0.0.0): Link Down (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;slot 1: empty&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Other host: Secondary - Standby Ready&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Active time: 0 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;slot 0: ASA5520 hw/sw rev (2.0/8.4(4)) status (Up Sys)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface internetwork.wan (192.168.236.100): Normal (Monitored)&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface A.dmz (192.168.236.34): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface B.dmz (192.168.236.2): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface C.dmz (192.168.236.66): Normal (Not-Monitored)&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface xerox.network (192.168.1.21): Normal (Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;Interface management (0.0.0.0): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;slot 1: empty&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the following interfaces:&lt;/P&gt;&lt;P&gt;--&amp;gt; A.dmz&lt;/P&gt;&lt;P&gt;--&amp;gt; B.dmz&lt;/P&gt;&lt;P&gt;--&amp;gt; C.dmz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This dmz's are sub-interfaces associated to the same physical interface, that are in shutdown mode, from the switching interface they are also in shutdown mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I understand from the active node standpoint we have a "Link Down" situation, but I don'e understand how can this be in "normal" state from the failover node stand point&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bruno Fernandes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442724#M238700</guid>
      <dc:creator>bruno.fernandes</dc:creator>
      <dc:date>2019-03-12T04:09:56Z</dc:date>
    </item>
    <item>
      <title>Hi Bruno, Its look to be L2</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442725#M238701</link>
      <description>&lt;P&gt;Hi Bruno,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its look to be L2 issue. Please check the vlan is created and extended in the switches&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2014 13:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442725#M238701</guid>
      <dc:creator>Abhirajsingh yadav</dc:creator>
      <dc:date>2014-05-07T13:43:37Z</dc:date>
    </item>
    <item>
      <title>Hi Yadav, The physical</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442726#M238702</link>
      <description>&lt;P&gt;Hi Yadav,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The physical interfaces associated with those dmz's/sub-intf is in shutdown mode…..so that's not the reason from my point of view&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bruno&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2014 14:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442726#M238702</guid>
      <dc:creator>bruno.fernandes</dc:creator>
      <dc:date>2014-05-07T14:30:31Z</dc:date>
    </item>
    <item>
      <title>Are the interfaces excluded</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442727#M238703</link>
      <description>&lt;P&gt;Are the interfaces excluded from failover monitoring in the config? ("no monitor-interface dmz")&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2014 15:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442727#M238703</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-07T15:45:47Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin, Yes does</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442728#M238705</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes does interfaces are not monitored, has a side note does dmz's are not being use now….also I don't have a specific "no monitor dmz" in the config !!!! but I'm 100% positive that I have uncheck the box regarding the monitoring option for does dmz's (in ASDM) ……but I will try&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;BF&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2014 20:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442728#M238705</guid>
      <dc:creator>bruno.fernandes</dc:creator>
      <dc:date>2014-05-07T20:59:52Z</dc:date>
    </item>
    <item>
      <title>I haven't a spare pair to try</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442729#M238708</link>
      <description>&lt;P&gt;I haven't a spare pair to try it on but I suspect your earlier comment about them being shutdown will exclude them from monitoring - even without the "no monitor-interface ___" command. That would make sense since if they are configured shutdown there's no way they will be up on either the active or standby unit.&lt;/P&gt;&lt;P&gt;...so bottom line would be that what you see in "show failover" is completely normal.&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2014 22:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-4-failover-issue/m-p/2442729#M238708</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-07T22:50:54Z</dc:date>
    </item>
  </channel>
</rss>

