<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you post your failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491822#M268117</link>
    <description>&lt;P&gt;Can you post your failover config from both devices? How are the ASA failover interfaces cabled?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Mar 2014 19:39:44 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2014-03-21T19:39:44Z</dc:date>
    <item>
      <title>ASA Failover trouble</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491821#M268114</link>
      <description>&lt;P&gt;We have a Pair of ASA-5585 System configured as an Active/Standby pair.&lt;/P&gt;&lt;P&gt;Every hour the system fails to to the current standby node. This has been an ongoing issue.&lt;/P&gt;&lt;P&gt;here is a sample of that we are seeing at the time of the failover on the log.&lt;/P&gt;&lt;P&gt;Mar 21 2014 10:12:58: %ASA-1-103001: (Secondary) No response from other firewall (reason code = 4).&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=406,op=20,my=Standby Ready,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720028: (VPN-Secondary) HA status callback: Peer state Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=401,op=0,my=Standby Ready,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720024: (VPN-Secondary) HA status callback: Control channel is down.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=402,op=0,my=Standby Ready,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720025: (VPN-Secondary) HA status callback: Data channel is down.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-315011: SSH session from 153.90.168.22 on interface management for user "admin" disconnected by SSH server, reason: "Terminated by operator" (0x35)&amp;nbsp;&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-315011: SSH session from 153.90.168.22 on interface management for user "admin" disconnected by SSH server, reason: "Terminated by operator" (0x35)&amp;nbsp;&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-5-611103: User logged out: Uname: admin&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-5-611103: User logged out: Uname: admin&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-1-104001: (Secondary) Switching to ACTIVE - HELLO not heard from mate.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720037: (VPN-Secondary) HA progression callback: id=3,seq=200,grp=0,event=200,op=4,my=Just Active,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720048: (VPN-Secondary) FSM action trace begin: state=, last event=, func=vpnfo_fsm_active_fast.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720049: (VPN-Secondary) FSM action trace end: state=, last event=, return=0, func=vpnfo_fsm_active_fast.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=401,op=0,my=Active Drain,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720024: (VPN-Secondary) HA status callback: Control channel is down.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=402,op=0,my=Active Drain,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720025: (VPN-Secondary) HA status callback: Data channel is down.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720037: (VPN-Secondary) HA progression callback: id=3,seq=200,grp=0,event=201,op=4,my=Active Drain,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720048: (VPN-Secondary) FSM action trace begin: state=, last event=, func=vpnfo_fsm_active_drain.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720049: (VPN-Secondary) FSM action trace end: state=, last event=, return=0, func=vpnfo_fsm_active_drain.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720037: (VPN-Secondary) HA progression callback: id=3,seq=200,grp=0,event=202,op=4,my=Active Applying Config,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720048: (VPN-Secondary) FSM action trace begin: state=, last event=, func=vpnfo_fsm_active_pre_config.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720049: (VPN-Secondary) FSM action trace end: state=, last event=, return=0, func=vpnfo_fsm_active_pre_config.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720037: (VPN-Secondary) HA progression callback: id=3,seq=200,grp=0,event=203,op=4,my=Active Config Applied,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720048: (VPN-Secondary) FSM action trace begin: state=, last event=, func=vpnfo_fsm_active_post_config.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720049: (VPN-Secondary) FSM action trace end: state=, last event=, return=0, func=vpnfo_fsm_active_post_config.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720037: (VPN-Secondary) HA progression callback: id=3,seq=200,grp=0,event=204,op=4,my=Active,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720048: (VPN-Secondary) FSM action trace begin: state=, last event=, func=vpnfo_fsm_active.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720039: (VPN-Secondary) VPN failover client is transitioning to active state&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-7-720049: (VPN-Secondary) FSM action trace end: state=, last event=, return=0, func=vpnfo_fsm_active.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720032: (VPN-Secondary) HA status callback: id=3,seq=200,grp=0,event=405,op=130,my=Active,peer=Failed.&lt;BR /&gt;Mar 21 2014 10:12:58: %ASA-6-720027: (VPN-Secondary) HA status callback: My state Active.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491821#M268114</guid>
      <dc:creator>jakimm.mt</dc:creator>
      <dc:date>2019-03-12T03:59:01Z</dc:date>
    </item>
    <item>
      <title>Can you post your failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491822#M268117</link>
      <description>&lt;P&gt;Can you post your failover config from both devices? How are the ASA failover interfaces cabled?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 19:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491822#M268117</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2014-03-21T19:39:44Z</dc:date>
    </item>
    <item>
      <title>Here is the fail-over config</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491823#M268121</link>
      <description>&lt;P&gt;Here is the fail-over config on the active ASA&lt;BR /&gt;the links for management on the systems are through a pair of 2960 switches that are port channeled together and is separate data centers.&lt;BR /&gt;also both ASAs are connected to a pair of Nexus 7k core switches to make up the core of our network.&lt;/P&gt;&lt;P&gt;"failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface failover GigabitEthernet0/0&lt;BR /&gt;failover polltime unit msec 200 holdtime msec 800&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link state GigabitEthernet0/1&lt;BR /&gt;failover interface ip failover 169.254.255.1 255.255.255.252 standby 169.254.255.2&lt;BR /&gt;failover interface ip state 169.254.255.5 255.255.255.252 standby 169.254.255.6"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is the config from the Standby node.&lt;/P&gt;&lt;P&gt;"failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface failover GigabitEthernet0/0&lt;BR /&gt;failover polltime unit msec 200 holdtime msec 800&lt;BR /&gt;failover polltime interface msec 500 holdtime 5&lt;BR /&gt;failover key *****&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link state GigabitEthernet0/1&lt;BR /&gt;failover interface ip failover 169.254.255.1 255.255.255.252 standby 169.254.255.2&lt;BR /&gt;failover interface ip state 169.254.255.5 255.255.255.252 standby 169.254.255.6"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2014 22:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/2491823#M268121</guid>
      <dc:creator>jakimm.mt</dc:creator>
      <dc:date>2014-03-24T22:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover trouble</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/3321748#M268124</link>
      <description>&lt;P&gt;Hi did you ever get this resolved. We're seeing a similar problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks so much!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-trouble/m-p/3321748#M268124</guid>
      <dc:creator>tom.wilcox@cdtfa.ca.gov</dc:creator>
      <dc:date>2018-01-30T16:05:10Z</dc:date>
    </item>
  </channel>
</rss>

