<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tracking Route from a Standby unit in a Active/Standby ASA array in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831633#M26623</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Could you please share the failover configuration and the &lt;STRONG&gt;show failover&lt;/STRONG&gt; output?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2019 17:46:44 GMT</pubDate>
    <dc:creator>Julio E. Moisa</dc:creator>
    <dc:date>2019-04-03T17:46:44Z</dc:date>
    <item>
      <title>Tracking Route from a Standby unit in a Active/Standby ASA array</title>
      <link>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831630#M26622</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured in an Active/standby array of ASAs a route tracking service to some destinations, each destination has a main and a secondary link.&lt;/P&gt;&lt;P&gt;Tracking service is not the issue, we found in our syslog server events from our active unit saying it is denying inbound icmp packets going to our standby unit. These icmp packets are coming from the destinations configured in our tracking service.&lt;/P&gt;&lt;P&gt;So, as we see it, our Active unit (as excepted) as well as our Standby unit (weird) are executing the route tracking service, and Active unit is rejecting replies sent to Standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following log is from Active unit (values were changed for privacy):&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP1} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP2} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP3} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP4} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP5} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP6} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Apr 03 2019 11:18:36: %ASA-3-106014: Deny inbound icmp src {Interface-Name}:{TrackingDestination-IP7} dst {Interface-Name}:{StandbyUnit-IP} (type 0, code 0)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Standby unit should not be tracking routes (unless it become Active). Is there a way to stop this tracking process in the standby unit?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831630#M26622</guid>
      <dc:creator>obadillaa</dc:creator>
      <dc:date>2020-02-21T17:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Route from a Standby unit in a Active/Standby ASA array</title>
      <link>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831633#M26623</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Could you please share the failover configuration and the &lt;STRONG&gt;show failover&lt;/STRONG&gt; output?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 17:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831633#M26623</guid>
      <dc:creator>Julio E. Moisa</dc:creator>
      <dc:date>2019-04-03T17:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Tracking Route from a Standby unit in a Active/Standby ASA array</title>
      <link>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831651#M26624</link>
      <description>&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;{hostname}/pri/act# sho failover &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Failover On &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Failover unit Primary&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Failover LAN Interface: fo_st_link Port-channel1 (up)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Reconnect timeout 0:00:00&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface Policy 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Monitored Interfaces 9 of 216 maximum&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;MAC Address Move Notification Interval not set&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Version: Ours x.x(x)xx, Mate x.x(x)xx&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Last Failover at: 18:37:44 CST Mar 29 2019&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;This host: Primary - Active &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Active time: 407617 (sec)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;slot 0: ASA5525 hw/sw rev (1.0/x.x(x)xx) status (Up Sys)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface OUTSIDE (a.a.a.251): Normal (Monitored)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface INSIDE (b.b.b.34): Normal (Monitored)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface {Interface-Name} (c.c.c.49): Normal (Monitored) &amp;lt;----Interface used for tracking service&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface management (0.0.0.0): No Link (Waiting)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Other host: Secondary - Standby Ready &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Active time: 6421 (sec)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;slot 0: ASA5525 hw/sw rev (1.0/x.x(x)xx) status (Up Sys)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface OUTSIDE (a.a.a.252): Normal (Monitored)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface INSIDE (b.b.b.35): Normal (Monitored)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface {Interface-Name} (c.c.c.50): Normal (Monitored) &amp;lt;----Interface used for tracking service&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Interface management (0.0.0.0): No Link (Waiting)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Stateful Failover Logical Update Statistics&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Link : fo_st_link Port-channel1 (up)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Stateful Obj xmit xerr rcv rerr &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;General 39867278 0 432424 822 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;sys cmd 215458 0 215455 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;up time 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;RPC services 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TCP conn 5044678 0 26521 28 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;UDP conn 34514537 0 189973 771 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;ARP tbl 86698 0 401 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Xlate_Timeout 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;IPv6 ND tbl 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN IKEv1 SA 619 0 10 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN IKEv1 P2 2146 0 31 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN IKEv2 SA 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN IKEv2 P2 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN CTCP upd 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN SDI upd 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;VPN DHCP upd 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Route Session 913 0 0 23 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Router ID 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;User-Identity 2229 0 33 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;CTS SGTNAME 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;CTS PAC 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TrustSec-SXP 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;IPv6 Route 0 0 0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;STS Table 0 0 0 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Logical Update Queue Information&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Cur Max Total&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Recv Q: 0 30 453276&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Xmit Q: 0 158 44626509&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;--- Failover Cfg ---&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;failover&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;failover lan unit primary&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;failover lan interface fo_st_link Port-channel1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;failover link fo_st_link Port-channel1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;failover interface ip fo_st_link d.d.d.253 255.255.255.252 standby d.d.d.254&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;failover ipsec pre-shared-key *****&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 18:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-route-from-a-standby-unit-in-a-active-standby-asa-array/m-p/3831651#M26624</guid>
      <dc:creator>obadillaa</dc:creator>
      <dc:date>2019-04-03T18:07:51Z</dc:date>
    </item>
  </channel>
</rss>

