<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510 - Backup ISP interface does not failback in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173259#M359514</link>
    <description>&lt;P&gt;&lt;BR /&gt;Cisco ASA 5510 ASA 8.2(5)&lt;BR /&gt;Set up the backup ISP per &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/produ" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Basically vanilla configuration&lt;/P&gt;&lt;P&gt;The SLA Target is the DG of the Primary Outside Interface - &lt;BR /&gt;The interface will fall over to backup ISP (a DHCP interface). We have seen this occur when APPLYing a change via Cisco ASDM as well as 'planned' cutovers). &lt;BR /&gt;The issue is that it does not fall back when the SLA Monitor sees the Target. &lt;BR /&gt;&lt;EM&gt;sla monitor operational-state &lt;/EM&gt;reflects a &lt;BR /&gt;&lt;EM&gt;Latest Operation return code: ok&lt;/EM&gt;. &lt;/P&gt;&lt;P&gt;However the &lt;EM&gt;show route &lt;/EM&gt;reflects the backup route. &lt;BR /&gt;The way I get it back is by bringing down the backup interface. &lt;BR /&gt;I thought the following may be helpful: &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_no" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_no&lt;/A&gt;te09186a0080bc8549.shtml&lt;BR /&gt;But this reflects a situation in which the routing table is rebuilt and the original Primary gateway is reinstated. &lt;BR /&gt;Again, our route table does not reflect the Primary (until I pull the cable). &lt;/P&gt;&lt;P&gt;One thing I did notice, now, is that the routing table (with the backup) does not show as a S* but d* (lowercase &lt;/P&gt;&lt;P&gt;d, not capital D for EIGRP) &lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.29.0 255.255.255.0 is directly connected, &lt;/P&gt;&lt;P&gt;inside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 50.196.236.120 255.255.255.248 is directly connected, &lt;/P&gt;&lt;P&gt;outside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.39.0 255.255.255.0 is directly connected, dmz&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 is directly connected, &lt;/P&gt;&lt;P&gt;Backup&lt;BR /&gt;d*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 192.168.1.254, Backup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wondering what would resolve the issue, so the ASA failbacks to the Primary once it is recognized. &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:19:24 GMT</pubDate>
    <dc:creator>OSG_DanCisco</dc:creator>
    <dc:date>2019-03-12T01:19:24Z</dc:date>
    <item>
      <title>ASA5510 - Backup ISP interface does not failback</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173259#M359514</link>
      <description>&lt;P&gt;&lt;BR /&gt;Cisco ASA 5510 ASA 8.2(5)&lt;BR /&gt;Set up the backup ISP per &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/produ" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Basically vanilla configuration&lt;/P&gt;&lt;P&gt;The SLA Target is the DG of the Primary Outside Interface - &lt;BR /&gt;The interface will fall over to backup ISP (a DHCP interface). We have seen this occur when APPLYing a change via Cisco ASDM as well as 'planned' cutovers). &lt;BR /&gt;The issue is that it does not fall back when the SLA Monitor sees the Target. &lt;BR /&gt;&lt;EM&gt;sla monitor operational-state &lt;/EM&gt;reflects a &lt;BR /&gt;&lt;EM&gt;Latest Operation return code: ok&lt;/EM&gt;. &lt;/P&gt;&lt;P&gt;However the &lt;EM&gt;show route &lt;/EM&gt;reflects the backup route. &lt;BR /&gt;The way I get it back is by bringing down the backup interface. &lt;BR /&gt;I thought the following may be helpful: &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_no" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_no&lt;/A&gt;te09186a0080bc8549.shtml&lt;BR /&gt;But this reflects a situation in which the routing table is rebuilt and the original Primary gateway is reinstated. &lt;BR /&gt;Again, our route table does not reflect the Primary (until I pull the cable). &lt;/P&gt;&lt;P&gt;One thing I did notice, now, is that the routing table (with the backup) does not show as a S* but d* (lowercase &lt;/P&gt;&lt;P&gt;d, not capital D for EIGRP) &lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.29.0 255.255.255.0 is directly connected, &lt;/P&gt;&lt;P&gt;inside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 50.196.236.120 255.255.255.248 is directly connected, &lt;/P&gt;&lt;P&gt;outside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.39.0 255.255.255.0 is directly connected, dmz&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 is directly connected, &lt;/P&gt;&lt;P&gt;Backup&lt;BR /&gt;d*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 192.168.1.254, Backup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wondering what would resolve the issue, so the ASA failbacks to the Primary once it is recognized. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173259#M359514</guid>
      <dc:creator>OSG_DanCisco</dc:creator>
      <dc:date>2019-03-12T01:19:24Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - Backup ISP interface does not failback</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173260#M359517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mind sharing the sla and interface configuration? The output of the "&lt;STRONG&gt;show route&lt;/STRONG&gt;" command will be useful too.&lt;/P&gt;&lt;P&gt;Also the " &lt;STRONG&gt;sho sla monitor operational-state&lt;/STRONG&gt;" output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "&lt;STRONG&gt;d*&lt;/STRONG&gt;" letter you see is used for routes learned via DHCP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Mar 2013 20:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173260#M359517</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-29T20:24:56Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - Backup ISP interface does not failback</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173261#M359519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share your show run?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to see if you have ip verify enable,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regar&lt;SPAN style="font-size: 10pt;"&gt;ds&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Mar 2013 23:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-backup-isp-interface-does-not-failback/m-p/2173261#M359519</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-29T23:09:12Z</dc:date>
    </item>
  </channel>
</rss>

