<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2130 ASA mode management interface failover problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/2130-asa-mode-management-interface-failover-problem/m-p/3886783#M25305</link>
    <description>&lt;P&gt;Only data path interfaces should be setup with standby addresses.&lt;/P&gt;
&lt;P&gt;Your ASA management1/1 addresses should not be included in the failover setup. Each management interface should have a unique IP address (and MAC address when using locally administered addresses such as you are using).&lt;/P&gt;
&lt;P&gt;When a unit changes role, the management interface address will remain the same.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2019 05:56:20 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-07-09T05:56:20Z</dc:date>
    <item>
      <title>2130 ASA mode management interface failover problem</title>
      <link>https://community.cisco.com/t5/network-security/2130-asa-mode-management-interface-failover-problem/m-p/3886566#M25303</link>
      <description>&lt;P&gt;I have an Active/Standby pair of 2130 appliances that is having a problem with the management interfaces when failing over from the primary to the secondary. When failover is invoked, the IP Address of the primary does not move to the standby and is unreachable. When I console into the primary 2130, it is up and functioning as the primary, but cannot access via ssh. When the secondary comes back (was intially the primary and now the secondary) I can ssh to the standby IP Address, but not the primary IP Address. Wondering if anyone else has experienced this also?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how I have the management interfaces and failover configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PRIMARY 2130&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;mac-address 12ff.0000.0005 standby 12ff.0000.0006&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.10 255.255.255.0 standby 168.192.1.11&lt;/P&gt;&lt;P&gt;route management 0.0.0.0 0.0.0.0 192.1168.1.1 1&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface FAILOVER Port-channel3&lt;BR /&gt;failover polltime unit 1 holdtime 3&lt;BR /&gt;failover polltime interface 3 holdtime 15&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link FAILOVER Port-channel3&lt;BR /&gt;failover interface ip FAILOVER 1.1.1.1 255.255.255.252 standby 1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SECONDARY 2130&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;mac-address 12ff.0000.0005 standby 12ff.0000.0006&lt;BR /&gt;nameif management&lt;BR /&gt;ip address 192.168.1.10 255.255.255.0 standby 168.192.1.11&lt;/P&gt;&lt;P&gt;route management 0.0.0.0 0.0.0.0 192.1168.1.1 1&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface FAILOVER Port-channel3&lt;BR /&gt;failover polltime unit 1 holdtime 3&lt;BR /&gt;failover polltime interface 3 holdtime 15&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link FAILOVER Port-channel3&lt;BR /&gt;failover interface ip FAILOVER 1.1.1.1 255.255.255.252 standby 1.1.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 19:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2130-asa-mode-management-interface-failover-problem/m-p/3886566#M25303</guid>
      <dc:creator>MARTIN HUERTER</dc:creator>
      <dc:date>2019-07-08T19:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: 2130 ASA mode management interface failover problem</title>
      <link>https://community.cisco.com/t5/network-security/2130-asa-mode-management-interface-failover-problem/m-p/3886783#M25305</link>
      <description>&lt;P&gt;Only data path interfaces should be setup with standby addresses.&lt;/P&gt;
&lt;P&gt;Your ASA management1/1 addresses should not be included in the failover setup. Each management interface should have a unique IP address (and MAC address when using locally administered addresses such as you are using).&lt;/P&gt;
&lt;P&gt;When a unit changes role, the management interface address will remain the same.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 05:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2130-asa-mode-management-interface-failover-problem/m-p/3886783#M25305</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-09T05:56:20Z</dc:date>
    </item>
  </channel>
</rss>

