<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What license do you have in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490364#M268438</link>
    <description>&lt;P&gt;What license do you have installed on your ASAs?&amp;nbsp; You need to have a security plus license for failover to work.&lt;/P&gt;&lt;P&gt;You can also issue the command show failover history to get more info on what is going on.&lt;/P&gt;&lt;P&gt;Have you check the logs to see if there is anything that might point to the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
    <pubDate>Mon, 10 Mar 2014 12:04:44 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-03-10T12:04:44Z</dc:date>
    <item>
      <title>ASA 5505 Active Standby Failover Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490363#M268430</link>
      <description>&lt;P&gt;Hello:&lt;BR /&gt;&lt;BR /&gt;I am trying to setup active/standby failover on a pair of ASA 5505's that have the security plus license on them.&amp;nbsp; Whenever I enable failover though, they seem to not want to talk to each other and I am at a loss as to why.&lt;/P&gt;&lt;P&gt;In terms of setup of connections, ASA01 port 0/4 connects to Switch01 port 1/0/21 and ASA02 port 0/4 connects to Switch01 port 1/0/22.&amp;nbsp; For all ports they are set as switchport access and have the appropriate vlan.&lt;/P&gt;&lt;P&gt;From the switch, I can ping the interface on ASA01 but not ASA02.&lt;/P&gt;&lt;P&gt;Attached are the three configuration and some diagnostic configuration printouts.&lt;/P&gt;&lt;P&gt;Can anyone advise on what I am missing to make this work?&lt;/P&gt;&lt;P&gt;Thanks!&lt;BR /&gt;Josh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:55:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490363#M268430</guid>
      <dc:creator>joshabts</dc:creator>
      <dc:date>2019-03-12T03:55:13Z</dc:date>
    </item>
    <item>
      <title>What license do you have</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490364#M268438</link>
      <description>&lt;P&gt;What license do you have installed on your ASAs?&amp;nbsp; You need to have a security plus license for failover to work.&lt;/P&gt;&lt;P&gt;You can also issue the command show failover history to get more info on what is going on.&lt;/P&gt;&lt;P&gt;Have you check the logs to see if there is anything that might point to the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490364#M268438</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-03-10T12:04:44Z</dc:date>
    </item>
    <item>
      <title>Yes, as I mentioned, I have</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490365#M268442</link>
      <description>&lt;P&gt;Yes, as I mentioned, I have the security plus license on both ASAs.&lt;/P&gt;&lt;P&gt;I am not seeing much in terms of logs which is why I am a little stuck. &amp;nbsp;From the show failover history on ASA01 I get the following which the 10:07 is roughly when I enabled it again this morning in my testing attempt:&lt;/P&gt;&lt;P&gt;01:19:15 UTC Mar 10 2014&lt;BR /&gt;Active &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Set by the config command&lt;/P&gt;&lt;P&gt;10:07:47 UTC Mar 10 2014&lt;BR /&gt;Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Negotiation &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Set by the config command&lt;/P&gt;&lt;P&gt;10:08:33 UTC Mar 10 2014&lt;BR /&gt;Negotiation &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Just Active &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;No Active unit found&lt;/P&gt;&lt;P&gt;10:08:33 UTC Mar 10 2014&lt;BR /&gt;Just Active &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active Drain &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; No Active unit found&lt;/P&gt;&lt;P&gt;10:08:33 UTC Mar 10 2014&lt;BR /&gt;Active Drain &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active Applying Config &amp;nbsp; &amp;nbsp; No Active unit found&lt;/P&gt;&lt;P&gt;10:08:33 UTC Mar 10 2014&lt;BR /&gt;Active Applying Config &amp;nbsp; &amp;nbsp; Active Config Applied &amp;nbsp; &amp;nbsp; &amp;nbsp;No Active unit found&lt;/P&gt;&lt;P&gt;10:08:33 UTC Mar 10 2014&lt;BR /&gt;Active Config Applied &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; No Active unit found&lt;/P&gt;&lt;P&gt;10:47:17 UTC Mar 10 2014&lt;BR /&gt;Active &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Set by the config command&lt;/P&gt;&lt;P&gt;==========================================================================&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490365#M268442</guid>
      <dc:creator>joshabts</dc:creator>
      <dc:date>2014-03-10T12:32:45Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490366#M268446</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Actually the secondary Unit looks good in regards to failover:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE style="color: rgb(0, 0, 0); line-height: normal;"&gt;
Failover unit Secondary
Failover LAN Interface: FAILOVER_LAN Vlan50 (up)&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But The primary ASA failover link is still down&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE style="color: rgb(0, 0, 0); line-height: normal;"&gt;
Failover LAN Interface: FAILOVER_LAN Vlan50 (Failed - No Switchover)&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you check status on the Switch for ports connecting to the ASA, change cables as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: when you ping from the switch the ARP table pointing to the primary ASA IP address belongs to which Firewal. ASA Primary or Secondary?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490366#M268446</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-03-10T12:37:42Z</dc:date>
    </item>
    <item>
      <title>Have you tried changing the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490367#M268449</link>
      <description>&lt;P&gt;Have you tried changing the cable between the ASAs?&lt;/P&gt;&lt;P&gt;Have you tested connectivity between the ASAs?&amp;nbsp; set an IP address on the interface and ping between them. Please let me know the results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490367#M268449</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-03-10T12:42:22Z</dc:date>
    </item>
    <item>
      <title>That is what I thought too</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490368#M268452</link>
      <description>&lt;P&gt;That is what I thought too Julio, and that is why I got more confused, because the primary (the one showing down) is the only one I *can* ping from the switch....&lt;/P&gt;&lt;P&gt;You can see the interface status in my sw01.txt file attached where I ran a sh int gi1/0/21. &amp;nbsp;It is showing up/up. &amp;nbsp;I have also verified by changing the vlan that port accesses and am able to communicate over it, so it isn't a bad cable/port...and I can ping it as noted.&lt;/P&gt;&lt;P&gt;The arp table on the switch for the 10.0.50.1 (primary failover interface ip) shows the mac address of the primary asa vlan 50 interface. &amp;nbsp;I would think that is as expected then.&lt;/P&gt;&lt;P&gt;So I am at a loss as to why from the switch I can't ping the secondary (unless that makes sense since it hasn't brought up the secondary address since it hasn't joined the primary yet) but it shows link up, yet I can ping the primary but it shows link down.&lt;/P&gt;&lt;P&gt;*Puzzled*.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:44:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490368#M268452</guid>
      <dc:creator>joshabts</dc:creator>
      <dc:date>2014-03-10T12:44:21Z</dc:date>
    </item>
    <item>
      <title>I can ping between the ASAs</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490369#M268455</link>
      <description>&lt;P&gt;I can ping between the ASAs using another interface/vlan. &amp;nbsp;The failover interface I cannot ping as it seems to not have brought up the addresses yet on the secondary since it hasn't joined the primary.&lt;/P&gt;&lt;P&gt;From the switch I can ping either on an alternate vlan and on the failover vlan I can only ping the primary asa.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490369#M268455</guid>
      <dc:creator>joshabts</dc:creator>
      <dc:date>2014-03-10T12:45:45Z</dc:date>
    </item>
    <item>
      <title>Remove the failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490370#M268458</link>
      <description>&lt;P&gt;Remove the failover configuration.&amp;nbsp; then set an IP on the failover interface of both ASAs and see if you can ping between them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remeber to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490370#M268458</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-03-10T12:57:25Z</dc:date>
    </item>
    <item>
      <title>Hi, can you please paste me</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490371#M268460</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please paste me your swtich sh vlan output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it looks like you vlan doesn't exist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2014 11:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-active-standby-failover-configuration-issue/m-p/2490371#M268460</guid>
      <dc:creator>khalid.meraj</dc:creator>
      <dc:date>2014-03-18T11:43:24Z</dc:date>
    </item>
  </channel>
</rss>

