<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with ASA active/standby set-up after migrating to new IS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388920#M309977</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&amp;nbsp; nope - no sub interfaces on the ASAs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2013 18:10:52 GMT</pubDate>
    <dc:creator>mitchen</dc:creator>
    <dc:date>2013-11-08T18:10:52Z</dc:date>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new ISP circuits</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388892#M309949</link>
      <description>&lt;P&gt;We have an Active/Standby ASA5540 firewall set-up with the Primary Active unit at our head office site (Site A) and the Secondary Standby unit at our DR site (Site B)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both sites had their "outside" interfaces directly connected to our ISP (We connect the ASA outside interface to the provider's NTE at each site)&amp;nbsp;&amp;nbsp; This all seemed to work reasonably well - our active traffic would go through Site A and, in the event of a failure with Site A firewall or interface, comms would failover to Site B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently decided to upgrade the bandwidth of our outside links to the ISP.&amp;nbsp; This meant getting completely new circuits installed and new NTEs but we requested that we keep the same IP Addressing for the new circuits (we have a number of VPN connections so didn't want to have to be changing configuration)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, come time to move to the new circuits, we presumed it would just be a case of changing the interface speed on the ASA interface (from 10 to 100) and moving the cables across from old NTE to new NTE.&amp;nbsp; Meanwhile the ISP would activate the "new" ports on their network switch and shutdown the "old"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ports.&amp;nbsp;&amp;nbsp; And this could be carried out relatively quickly to minimise any disruption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this is not how it panned out.&amp;nbsp; It seems that when the ISP activates the new ports, Site B takes over as Active firewall and the Site A firewall has its outside interface marked as "failed"&amp;nbsp; - The ISP had to shutdown the Site B link in order to allow us to pass traffic through the Site A firewall and circuit again.&amp;nbsp; And we are left with the situation where we effectively DON'T have our Active/Standby set-up with automatic failover any longer!&amp;nbsp; We can either have Site A active and passing traffic and Site B marked as "failed" on its outside interface or vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know too much about the ISP's set-up to be honest but, as far as I'm aware, the ISP connects both the circuits for Site A and Site B to the same network switch in their datacentre and to the same VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone suggest what the problem might be and how to resolve it?&amp;nbsp; I'm assuming it has to be something at the ISP end since I don't really understand what else could be necessary from our point of view (i.e. what else would we need to do other than move the cables and configure the new interface speed)?&amp;nbsp;&amp;nbsp; Its as if there is some sort of conflict on the ISP's network switch - I don't know if it is something to do with the way the standby ASA takes over the active ASA IP and MAC address and that somehow gets the ISP network switch in a state of confusion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas/suggestions?&amp;nbsp; Naturally we are a bit disappointed since we hoped this would be a relatively straightforward task to migrate to our new circuits with increased bandwidth!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388892#M309949</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2019-03-12T02:58:23Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388893#M309950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where I've seen ASA interfaces, particularly outside ones, showing as "failed" is where they can't actually communicate with each other. I'm not sure if its ICMP that is required between then, but I've certainly seen similar issues where the two ASA outside cards can't ping between each other. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you run a ping from ASA "B" to the outside address of ASA "A" does it work? I suspect not, and this is the route cause of your issue. If this is the case, then you'll need to get your ISP involved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.barryhesk.com"&gt;Barry Hesk&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.intrinsic-comms.co.uk"&gt;Intrinsic Network Solutions&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 09:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388893#M309950</guid>
      <dc:creator>barry</dc:creator>
      <dc:date>2013-10-31T09:16:34Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388894#M309951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And just as another thought... here's a left field guess. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I reckon your old circuits were layer 2 tails (in the same VLAN) that terminate in your ISPs data centre, again on the same VLAN. This means that all devices in the same VLAN can always communicate with each other. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I reckon your new circuits are layer 3 tails, and only one will be routed over at any given time (the current active circuit). This would explain why the "standby" ASA - whichever one it is - always shows its outside card as failed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would explain the exact problem you are seeing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I say, bit left field, but I reckon there is logic there...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.barryhesk.com"&gt;Barry Hesk&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.intrinsic-comms.co.uk"&gt;Intrinsic Network Solutions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 09:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388894#M309951</guid>
      <dc:creator>barry</dc:creator>
      <dc:date>2013-10-31T09:21:40Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388895#M309952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks Barry - some very helpful suggestions, your 2nd one in particular definitely sounds like a strong possibility?&amp;nbsp; Will try to find out more and will update and will let you know if we get any closer to resolving the issue or not...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 10:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388895#M309952</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-10-31T10:07:49Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388896#M309953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, a quick update.&amp;nbsp; We still haven't got this working successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISP have confirmed that the new circuits ARE layer 2 so seems that Barry's earlier suggestion (good though it was!) can't be the cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISP tried some manipulation of their switch(es) spanning tree set-up but to no avail - we can still only have one circuit active while the other one is marked as failed,&amp;nbsp; Can't ping between the outside interfaces (allowed ICMP first so &lt;EM&gt;should &lt;/EM&gt;have got a response if all was in order!) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see how the issue can be anything other than a switching issue in the ISP's network but, so far, they are at a loss to explain what the problem could be and we are left without automatic failover of our new circuits.&amp;nbsp; The ISP are going to continue to investigate offline but, if anyone has any suggestions or has seen similar in the past then further advice would certainly be appreciated.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 23:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388896#M309953</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-05T23:14:36Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388897#M309954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, look if your ISP did a change and it is not working and you are sure of this then why review the ASA. If the unit is at standby at this moment and the only interface that is affected is the outside then ISP ISP ISP.&lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 01:02:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388897#M309954</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-06T01:02:46Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388898#M309955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I'm fairly certain the issue is with the ISP &lt;STRONG&gt;but&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) there is no harm (in fact, some might consider it good practise) to ensure all other bases are covered - just in case &lt;/P&gt;&lt;P&gt;b) it's entirely possible that someone out there in the vast Cisco networking world has come across the same sort of situations, particularly those who work for ISPs with similar customer set-up (or customers with this set-up who have had similar problems with their ISP!), and can give pointers as to how to resolve it - even if that is simply evidence to go back to beat up the ISP with.&amp;nbsp; (Barry's suggestions above were very helpful indeed, for example, even if they may not ultimately have been the cause) &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;c) even if the problem is ultimately with the ISP, appreciating the dependencies etc can only help to gain a better understanding of the ASA devices themselves which is surely an aim of any technical forum?&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 16:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388898#M309955</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-06T16:04:56Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388899#M309956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand what you are saying and we are always happy to help but when the equipment that affects connectivity is not manageable that is where support forums or TAC case can't help&lt;SPAN __jive_emoticon_name="cry" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;. I would suggest calling the ISP and getting this escalated.&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388899#M309956</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-06T18:22:54Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388900#M309957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say that you have no connectivity between the ASAs &lt;STRONG&gt;"outside" &lt;/STRONG&gt;interfaces? Does your ISP have HSRP doing the gateway redudancy on their side? Can they confirm its ok?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A very easy thing to confirm the complete connectivity would be to ping the &lt;STRONG&gt;"standby"&lt;/STRONG&gt; IP address from the Active unit and then issue &lt;STRONG&gt;"show arp | inc outside"&lt;/STRONG&gt; (or replace the &lt;STRONG&gt;outside&lt;/STRONG&gt; with the actual name of your external interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can't see the &lt;STRONG&gt;"standby"&lt;/STRONG&gt; IP address in the &lt;STRONG&gt;"show arp"&lt;/STRONG&gt; output that means even the ARP isnt working between your sites. At this point it should be up to your ISP to check where the traffic stops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can see the &lt;STRONG&gt;"standby"&lt;/STRONG&gt; IP address in the Active units ARP then I am not sure what the problem is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the Failover operation has its own &lt;STRONG&gt;"debug"&lt;/STRONG&gt; command which is &lt;STRONG&gt;"debug fover"&lt;/STRONG&gt; in addition to multiple different parameters. I am not sure how much output it generates but I would use the additional options after the &lt;STRONG&gt;"debug fover"&lt;/STRONG&gt; if I were to use debug to help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should probably even be able to configure &lt;STRONG&gt;"capture"&lt;/STRONG&gt; on your ASA before you do any checking. You could capture traffic between the primary and standby IP address of the interface and see if anything is actually happening. I guess you can even go as far to capture the ARP messages and see if there is anything visible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388900#M309957</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-06T18:44:18Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388901#M309958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;thanks for the good advice and suggestions - very much appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know whether the ISP have HSRP doing the gateway/redundancy on their side but I don't &lt;EM&gt;think &lt;/EM&gt;so. I can try to confirm but getting information out of them on their set-up is often difficult, although we continue to pursue them on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to ping the standby IP address from the Active unit (I allowed ICMP so the firewalls themselves were definitely not blocking it)&amp;nbsp; Indeed I can't ping the Standby IP address from anywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, &lt;STRONG&gt;show arp | inc outside&lt;/STRONG&gt; DOES show the "standby" IP address in the output so ARP seems to be working at least?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if I can see the standby IP address in the Active unit's ARP table but can't seem to otherwise ping/communicate with the Standby unit over the outside interface then what could the problem be?&amp;nbsp; &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 12:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388901#M309958</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-07T12:48:01Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388902#M309959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post the output of the below just to be sure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run icmp &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And perhaps also&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run access-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am actually not sure how the ASA does with the ARP in a Failover pair. I rarely have to troubleshoot Failover. For the most part they seem to work flawlesly in our Datacenter environments &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output of &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show failover&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should list statistics at the bottom also related to ARP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you could also take the following output from the Standby unit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show arp | inc outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again depending what your external interface is named. Just to make sure that the same information is shown there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could actually run that command from the Active unit with this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover exec mate show arp | inc outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should send this command to the Standby unit through the Failover link and print its output to the Active units CLI &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; You can use that for other commands too if you want to do all from a single ASA unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also configure a capture on the Active firewall and perhaps even the Standby. The capture configured on the Active unit only applies to it. I dont think it captures the traffic on the Standby unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The capture configuration could be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list OUTSIDE-CAP permit ip host &lt;PRIMARY ip=""&gt; host &lt;SECONDARY ip=""&gt;&lt;/SECONDARY&gt;&lt;/PRIMARY&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list OUTSIDE-CAP permit ip host &lt;SECONDARY ip=""&gt; host &lt;PRIMARY ip=""&gt;&lt;/PRIMARY&gt;&lt;/SECONDARY&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture OUTSIDE-CAP type raw-data accesslist OUTSIDE-CAP interface outside buffer 1000000 circular-buffer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to configure the capture buffer to 33500000 also which is almost the maximum allowed if you want to run it for a long time. The &lt;STRONG&gt;"circular-buffer"&lt;/STRONG&gt; and the end specifies that the ASA will overwrite old information IF the buffer is filled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This could be done on both units if you want to make sure what traffic both see. You could then see the ICMP traffic. You would also catch the traffic that the ASA uses to monitor the Failover interface state. It uses protocol 105 (SCPS). This naturally requires that you are monitoring that interface. If I am not mistaken then a normal physical interface is monitored all the time but a logical interface requires the &lt;STRONG&gt;"monitor-interface"&lt;/STRONG&gt; command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view if any traffic is captured you can use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view the actual contents of the capture you can use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture OUTSIDE-CAP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Better yet, you could copy the capture to your computer with TFTP and open it with Wireshark to actually make sense of the output &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;copy /pcap capture:OUTSIDE-CAP t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://"&gt;ftp://&lt;/A&gt;&lt;SPAN&gt;&lt;HOST ip=""&gt;/OUTSIDE-CAP.pcap&lt;/HOST&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an actual capture output from one of our Failover pairs viewed with Wireshark (though it doesnt contain much and I removed the IPs as they are public naturally) You should see this between the monitored interface from both untis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/8/3/165386-CSC-FOVERCAP.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can remove the capture (and its contents with) with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no capture OUTSIDE-CAP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The created ACL you have to delete separately ofcourse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the captures on both units you would atleast have the chance to confirm that no traffic is "dissapearing" between the ASAs on the external interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how the ISP has configure the L2 segment between the ASAs and the L3 gateway(s). I guess you could ask them to make sure they can see both units MAC addresses all along the way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if any of this helps but some thoughts alteast what to look for &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have personally have an easier time solving these for our customers as I have access to both customer ASAs and the ISP core network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 13:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388902#M309959</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-07T13:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ASA active/standby set-up after migrating to ne</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388903#M309960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;some great suggestions and advice there, thanks very much (well worth 5 stars even if I still haven't solved my issue!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't know about the method to run commands on the standby unit from the active - very handy, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some sample output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier;"&gt;sh run icmp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier;"&gt;sh run access-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-group inbound in interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-group outbound in interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;("&lt;SPAN style="font-family: 'courier new', courier;"&gt;inbound&lt;/SPAN&gt;" ACL also contains a &lt;SPAN style="font-family: 'courier new', courier;"&gt;permit icmp any any &lt;/SPAN&gt;now but I'm not sure that is even needed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier;"&gt;sh failover &lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt;("real" IP addresses changed in output)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Failover On&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Failover unit Primary&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Failover LAN Interface: Failover GigabitEthernet0/1 (up)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Interface Policy 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Monitored Interfaces 2 of 250 maximum&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Version: Ours 7.2(5)10, Mate 7.2(5)10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Last Failover at: 18:57:46 GMT/BST Nov 5 2013&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This host: Primary - Active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 17735733 (sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 0: ASA5540 hw/sw rev (1.1/7.2(5)10) status (Up Sys)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside (1.1.1.2): Normal (Waiting)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface DMZ (0.0.0.0): No Link (Not-Monitored)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface inside (192.168.20.5): Normal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management (192.168.2.1): No Link (Not-Monitored)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 1: ASA-SSM-20 hw/sw rev (1.0/6.2(4)E4) status (Up/Up)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS, 6.2(4)E4, Up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Other host: Secondary - Failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 589 (sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 0: ASA5540 hw/sw rev (1.1/7.2(5)10) status (Up Sys)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside (1.1.1.3): Failed (Waiting)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface DMZ (0.0.0.0): Normal (Not-Monitored)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface inside (192.168.20.6): Normal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management (0.0.0.0): Normal (Not-Monitored)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 1: ASA-SSM-20 hw/sw rev (1.0/6.2(4)E4) status (Up/Up)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS, 6.2(4)E4, Up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Stateful Failover Logical Update Statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Link : Failover GigabitEthernet0/1 (up)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Stateful Obj&amp;nbsp;&amp;nbsp;&amp;nbsp; xmit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; xerr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rcv&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rerr&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; General&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1248457245 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2843085&amp;nbsp;&amp;nbsp;&amp;nbsp; 22992&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sys cmd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2366474&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2366459&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RPC services&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP conn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 312664258&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 134902&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9878&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP conn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 902624774&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 297382&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13108&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ARP tbl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 271594&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 288&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xlate_Timeout&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN IKE upd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 889667&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14158&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN IPSEC upd&amp;nbsp;&amp;nbsp; 29640478&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 29896&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN CTCP upd&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN SDI upd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN DHCP upd&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logical Update Queue Information&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cur&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Max&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Recv Q:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 82&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3652027&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xmit Q:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1024&amp;nbsp;&amp;nbsp;&amp;nbsp; 12293902460&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;On Standby:&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier;"&gt; show arp | inc outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside 1.1.1.2 0018.73d6.19e5 &lt;/SPAN&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside 1.1.1.1 001a.e2e6.bdfa 295&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(1.1.1.1 being the "default gateway" to the ISP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, good suggestion to capture traffic between the interfaces (and the circular buffer was also something new for me - previously, I had just been letting the buffer fill up with my captures then clearing manually!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, the captures show that both Active and Standby units send the SCPS (105) packets but no replies ever come back.&amp;nbsp; Similarly, when I attempt the pings - the captures show the ICMP packets being sent but no replies coming back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Active Unit capture ("real" public IP addresses changed)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;1239: 17:14:09.502888 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1240: 17:14:14.502522 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1241: 17:14:19.501911 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1242: 17:14:19.749366 1.1.1.2 &amp;gt; 1.1.1.3: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1243: 17:14:21.741706 1.1.1.2 &amp;gt; 1.1.1.3: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1244: 17:14:23.741508 1.1.1.2 &amp;gt; 1.1.1.3: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1245: 17:14:24.501408 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1246: 17:14:25.741416 1.1.1.2 &amp;gt; 1.1.1.3: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1247: 17:14:27.741096 1.1.1.2 &amp;gt; 1.1.1.3: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1248: 17:14:29.500981 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1249: 17:14:34.500447 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1250: 17:14:39.499958 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1251: 17:14:44.502659 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1252: 17:14:49.498997 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1253: 17:14:54.498494 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1254: 17:14:59.498005 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1255: 17:15:04.497517 1.1.1.2 &amp;gt; 1.1.1.3:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Standby Unit Capture ("real" public IP addresses changed)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;1209: 17:16:51.784001 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1210: 17:16:56.783574 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1211: 17:17:01.783040 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1212: 17:17:06.782567 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1213: 17:17:08.073375 1.1.1.3 &amp;gt; 1.1.1.2: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1214: 17:17:10.072292 1.1.1.3 &amp;gt; 1.1.1.2: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1215: 17:17:11.782003 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1216: 17:17:12.072078 1.1.1.3 &amp;gt; 1.1.1.2: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1217: 17:17:14.072063 1.1.1.3 &amp;gt; 1.1.1.2: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1218: 17:17:16.071666 1.1.1.3 &amp;gt; 1.1.1.2: icmp: echo request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1219: 17:17:16.781530 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1220: 17:17:21.780980 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1221: 17:17:26.780507 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;1222: 17:17:31.779988 1.1.1.3 &amp;gt; 1.1.1.2:&amp;nbsp; ip-proto-105, length 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess this confirms what we know i.e. that comms between the units on the outside interfaces aren't working but still doesn't explain &lt;EM&gt;why&lt;/EM&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it has to be something on the ISP's switching network - could it be something as simple as their STP set-up detects a loop condition and&amp;nbsp; "blocks" the standby unit, for some reason?&amp;nbsp; And if that is a possibility, why might it be happening?&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very puzzling?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any more suggestions and advice would be most welcome!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 17:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388903#M309960</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-07T17:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ASA active/standby set-up after migrating to ne</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388904#M309961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if I am reading this correctly then your Active unit is showing all the external links expected ARP information BUT the Standby unit only shows its own and gateways ARP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you configured the capture ACL bidirectionally on both units (so that it captures sent and received information) then we can clearly see that no traffic from either unit gets to the other unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would have to say that from my own perspective this is not something you should have to be tackling alone. The ISP should really help out troubleshooting the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The information you already have gathered should already be pretty good material to show the ISP that the connection between the sites simply is not working. And considering that they arent really providing the service you are paying them for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what more can be done from the devices you manage. I atleast feel that its unreasonable for the ISP to expect you to solve/troubleshoot this alone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to capture ARP traffic on the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface you can probably use this command for capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture ARP-CAPTURE ethernet-type arp interface outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other commands apply to this capture also. You can show it in the CLI and copy it to your computer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 17:43:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388904#M309961</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-07T17:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ASA active/standby set-up after migrating to ne</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388905#M309962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I &lt;EM&gt;think &lt;/EM&gt;the ARP info on both Active and Standby is as expected i.e. Active unit shows ARP entry for Standby unit and ISP default gateway.&amp;nbsp;&amp;nbsp; Standby unit shows ARP entry for Active unit and ISP default gateway.&amp;nbsp; This is what they currently show and I'm &lt;EM&gt;assuming &lt;/EM&gt;this is what should be expected (though not having gone into this level of detail on this side of things I'm not 100% sure?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captures definitely captured bidirectionally so confident that they show traffic from either unit not getting to the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cleared the arp outside entries on the standby ASA and tried the ARP capture you suggested.&amp;nbsp;&amp;nbsp; Interestingly, the ARP table immediately shows the ARP entry for the active ASA (nothing got captured in my packet capture for it i.e. I didn't actually see any ARP requests go out?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I then tried pinging the ISP's default gateway and the ARP capture shows ARP requests being sent for it but no replies?&amp;nbsp; However, the ARP table does eventually show an entry for it, as before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, I'm not too sure what i &lt;EM&gt;should &lt;/EM&gt;be expecting to see here? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I definitely agree with you that I'm reaching the point of exhaustion on what I can do to look into the issue myself.&amp;nbsp; In fairness, the ISP have said they are working on it but all they have really asked from me so far is for my ASA configs so I'm not sure they are looking in the right place as all the evidence would seem to point at the problem being with their set-up rather than with the ASAs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for all the assistance you have given me on this, it has been very useful and has helped me learn some more about the ASA interactions for one thing!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 18:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388905#M309962</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-07T18:03:48Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388906#M309963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I read your earlier post wrong. I was actually looking that your Standby ASA only had the its own and gateway information in the ARP table but it seems that both units have information about the other unit and gateway in the ARP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if this is the information transfered through the Failover link. This is 100% a guess on my part. Since we are not seeing any traffic reach the other unit on the external interface I would guess that the ARP information is the combined information what the units themselves see and "tell eachother" through the Failover link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would atleast tell why the ARP capture didnt show anything captured until you send ICMP to the gateway. But again, its just a guess. I would assume though if you see an ARP request in the capture you would need to see a reply for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 18:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388906#M309963</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-07T18:15:35Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388907#M309964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks, I'm not sure either - but your guess would certainly make sense.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's see what tomorrow brings - maybe the ISP will make some progress for me!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 18:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388907#M309964</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-07T18:17:48Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388908#M309965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only if the customer has stateful failover link defined ARP is replicated from Active to standby:&lt;/P&gt;&lt;H3&gt; &lt;A name="statef"&gt;Stateful Failover&lt;/A&gt; &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When stateful failover is enabled, the active unit continually passes &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; per-connection state information to the standby unit. After a failover occurs, &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the same connection information is available at the new active unit. Supported &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; end-user applications are not required to reconnect to keep the same &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; communication session. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The state information passed to the standby unit includes these: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The NAT translation table&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The TCP connection states&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The UDP connection states&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The ARP table&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Layer 2 bridge table (when it runs in the transparent firewall &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;mode)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The HTTP connection states (if HTTP replication is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enabled)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The ISAKMP and IPSec SA table&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The GTP PDP connection database&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The information that is not passed to the standby unit when stateful &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; failover is enabled includes these: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The HTTP connection table (unless HTTP replication is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;enabled)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The user authentication (uauth) table&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The routing tables&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;State information for security service &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;modules&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 18:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388908#M309965</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-07T18:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ASA active/standby set-up after migrating to ne</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388909#M309966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mitchen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to add my 2 cents here &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I definetly agree the problem is on the ISP side ( I mean that's for sure ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, due to the nature of the problem (1 of the Switch interfaces that belong to that same vlan needs to be shutdown ) let us know we could be dealing with a STP problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would encourage them to check for STP blocking the link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show spanning-tree vlan # &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And look for both ports (one of them should be on the blocking state).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also a Port-mirroring session on the switch side in order to capture all traffic being received would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com" rel="nofollow"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 19:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388909#M309966</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-11-07T19:01:25Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388910#M309967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so I understand we can explain multiple scenarios to the customer but the problem is to assume that the customer has X,Y and Z, if this was a configuration example question I would help but this is not the case. My intention is not to confuse the customer because he can go on with thousands of questions that don’t come into case because he does not manage the ISP devices. If for example the customer told me that this happened with HSRP setup that he controls I would be looking at that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that the customer and all of you understands my point and get the ISP involved so that they can fix the customer’s issue or tell us what they see that could be causing the failure that I still believe has nothing to do with the ASAs. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 22:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388910#M309967</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-07T22:43:36Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA active/standby set-up after migrating to new IS</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388911#M309968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jumora/Jouni - we &lt;EM&gt;do &lt;/EM&gt;have stateful failover so that explains the ARP info being replicated from Active to Standby and therefore what I am seeing makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio - yes, I agree - that's what I also suspect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jumora (and all!) - sorry, I should have made this clear in my original post:&amp;nbsp; &lt;STRONG&gt;Obviously,&amp;nbsp; &lt;/STRONG&gt;&lt;STRONG&gt;I DO have a call out with the ISP already (and have since escalated this with them) and I also believe the problem is at their end rather than the ASA's and have said as much to them right from the start! &lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, as I explained earlier in the thread I wanted to make sure I covered all bases by investigating everything at "my" end too - with the bonus of gathering more evidence to beat up the ISP with and increasing my own understanding of the ASA's and their interactions and dependencies.&amp;nbsp; In that regard, I'm very happy to have done so as I have had some great advice and suggestions from everyone (I don't want to neccessarily single anyone out as I'm grateful for all help but Jouni in particular has given some excellent troubleshooting tips which I'm sure will benefit myself, and hopefully others who have chanced upon this forum topic, in many other situations too)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that we are limited in what we can achieve given we (or I) have no control over the ISP side of things but it still seemed to me that it was worthwhile posing the question because there was every chance someone out there could have experienced similar (or could offer helpful troubleshooting advice and suggestions as has certainly been the case)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Happy to close the topic if it has gone outside the boundaries of what the Cisco forum is intended for.&amp;nbsp; And it's been useful for me even if it's been of no use to any other Cisco networkers!&amp;nbsp; &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2013 23:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-active-standby-set-up-after-migrating-to-new/m-p/2388911#M309968</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2013-11-07T23:31:12Z</dc:date>
    </item>
  </channel>
</rss>

