<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520 getting below error while getting replication from prim in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157655#M358019</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By giving below cmd &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show memory &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Free memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1465222416 bytes (68%)&lt;/P&gt;&lt;P&gt;Used memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 682261232 bytes (32%)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We dont have option show mem usage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Apr 2013 14:44:07 GMT</pubDate>
    <dc:creator>mphasis infosec</dc:creator>
    <dc:date>2013-04-17T14:44:07Z</dc:date>
    <item>
      <title>ASA 5520 getting below error while getting replication from primary firewall</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157648#M358003</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the primary firewall every thing seem to be fine, And we have configured failover device while config is getting replicated to the failover device we are getting below error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Cannot add policy to rule engine&lt;/P&gt;&lt;P&gt;ERROR: Unable to assign access-list Lan_out to interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IOS and Model are same.But all the config got replicated from primary to secondary but except the one access group command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-group Lan_out in interface inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks&lt;/P&gt;&lt;P&gt;Diwa&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157648#M358003</guid>
      <dc:creator>mphasis infosec</dc:creator>
      <dc:date>2019-03-12T01:30:08Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 getting below error while getting replication from prim</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157649#M358006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Havent faced this issue myself so this is just a pure guess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a chance that someone has been configuring the Secondary firewall and changed the "inside" interface "nameif" to something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could confirm this directly logging into the secondary unit and issuing the command "show run interface"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Somehow I think though that this might be something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 13:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157649#M358006</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-17T13:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 getting below error while getting replication from</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157650#M358007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have verified already and i have logged-in double checked in seconday firewall&lt;STRONG&gt; nameif inside&lt;/STRONG&gt;, which is same as primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Diwa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;&lt;IMG /&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 13:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157650#M358007</guid>
      <dc:creator>mphasis infosec</dc:creator>
      <dc:date>2013-04-17T13:29:26Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 getting below error while getting replication from prim</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157651#M358009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you taken "show run" output from both units and compared them with for example Microsoft Word or some other program to see if there is anything different?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could there be some issue with memory? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this some Failover setup that has been working before this issue? Or have you just added the secondary unit and you encountered the problem before the setup even got working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only sync/replication problem I have had with ASA A/S Failover was when the Sync got stuck and wouldnt go through. I ended up removing the Standby unit from the network. Erased its configuration and only configured the configurations required by the Failover and then the Configuration Sync went through without problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again these are just guesses and suggestions. I am not sure what the problem might be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157651#M358009</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-17T14:13:18Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 getting below error while getting replication from prim</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157652#M358011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first thing mentioned when searching information about the error message hints to a situation where there is not enough memory for the ACL configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think from some software level onwards the ASAs could actually be of different RAM setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that the ASAs have different amount of RAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could use "show version" on both units to confirm the RAM setup of each ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157652#M358011</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-17T14:19:51Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 getting below error while getting replication from prim</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157653#M358013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have compared primary &amp;amp; secondary unit running config using compare tool.&lt;/P&gt;&lt;P&gt;Every thing is identical except the one command is missing from the seconday &lt;STRONG&gt;access-group Lan_out in interface inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Changes which we are doing in the primary getting replicated without issue and also&lt;STRONG&gt; sh failover state&lt;/STRONG&gt; say&lt;/P&gt;&lt;P&gt; Sync Done - STANDBY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we found the RAM in primary unit 2 Gb &amp;amp; in secondary is 1 GB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are planning to erase the config and replicate once again with the primary unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Diwa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157653#M358013</guid>
      <dc:creator>mphasis infosec</dc:creator>
      <dc:date>2013-04-17T14:37:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 getting below error while getting replication from prim</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157654#M358016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have complicated ACLs which for example use "object-group" I imagine the ACLs grow very large and consume a lot of memory. Also other configurations which use the ACLs might be a cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could check what is the memory status on the Primary unit which has more RAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show memory usage&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:40:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157654#M358016</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-17T14:40:48Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 getting below error while getting replication from prim</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157655#M358019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By giving below cmd &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show memory &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Free memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1465222416 bytes (68%)&lt;/P&gt;&lt;P&gt;Used memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 682261232 bytes (32%)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We dont have option show mem usage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-getting-below-error-while-getting-replication-from/m-p/2157655#M358019</guid>
      <dc:creator>mphasis infosec</dc:creator>
      <dc:date>2013-04-17T14:44:07Z</dc:date>
    </item>
  </channel>
</rss>

