<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA HA Pair and OSPF with router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141065#M359794</link>
    <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;customer has ASA cluster pair which is running 8.2 (5) &lt;/P&gt;&lt;P&gt;This firewall is participating in the OSPF process, and the affected interface are in the "Area 0". "Remote stations" are also a Cisco components (eg, WS-C3750-24TS-S with 12.2 (44) SE5, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you perform "no failover active" the firewall cluster and also triggered by removing a cable&amp;nbsp; (not the SYNC interface) takes the standby node as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tests have shown that it can take up to ~ 60 seconds until the newly activated firewall works again(this really means everything is now up and running as it should do ),ping from the firewall to the Internet via LAN. Prior to the implementation of OSPF showed a non-measurable results, no ping loss though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are two questions at the moment &lt;/P&gt;&lt;P&gt;1 ) could this problem be solved by upgrading the ASA to 8.4 = already answered&lt;/P&gt;&lt;P&gt;2 ) any known&amp;nbsp; configuration parameters which we could apply on the router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also keep in mind&lt;/P&gt;&lt;P&gt;The standby becomes active almost immediately. Passing packets via that firewall takes that high amount of waiting time. The culprit might be the missing routing data (OSPF update …)&lt;/P&gt;&lt;P&gt;any advice on the OSPF please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:16:55 GMT</pubDate>
    <dc:creator>Lance Wendel</dc:creator>
    <dc:date>2019-03-12T01:16:55Z</dc:date>
    <item>
      <title>ASA HA Pair and OSPF with router</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141065#M359794</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;customer has ASA cluster pair which is running 8.2 (5) &lt;/P&gt;&lt;P&gt;This firewall is participating in the OSPF process, and the affected interface are in the "Area 0". "Remote stations" are also a Cisco components (eg, WS-C3750-24TS-S with 12.2 (44) SE5, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you perform "no failover active" the firewall cluster and also triggered by removing a cable&amp;nbsp; (not the SYNC interface) takes the standby node as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tests have shown that it can take up to ~ 60 seconds until the newly activated firewall works again(this really means everything is now up and running as it should do ),ping from the firewall to the Internet via LAN. Prior to the implementation of OSPF showed a non-measurable results, no ping loss though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are two questions at the moment &lt;/P&gt;&lt;P&gt;1 ) could this problem be solved by upgrading the ASA to 8.4 = already answered&lt;/P&gt;&lt;P&gt;2 ) any known&amp;nbsp; configuration parameters which we could apply on the router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also keep in mind&lt;/P&gt;&lt;P&gt;The standby becomes active almost immediately. Passing packets via that firewall takes that high amount of waiting time. The culprit might be the missing routing data (OSPF update …)&lt;/P&gt;&lt;P&gt;any advice on the OSPF please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141065#M359794</guid>
      <dc:creator>Lance Wendel</dc:creator>
      <dc:date>2019-03-12T01:16:55Z</dc:date>
    </item>
    <item>
      <title>ASA HA Pair and OSPF with router</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141066#M359795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Lance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would that 8.4 would be great as we support the exchange of&amp;nbsp; stateful information regarding routing protocols via the stateful link so after an event the secondary unit will take place and start routing as it has built the routing table with the primary unit via the stateful link info &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that I could help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 17:20:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141066#M359795</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T17:20:55Z</dc:date>
    </item>
    <item>
      <title>ASA HA Pair and OSPF with router</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141067#M359796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jcarvaja&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply, I have seen the release notes on the Cisco site and also came across the following &lt;/P&gt;&lt;P&gt;link &lt;A href="http://www.groupstudy.com/archives/ccielab/201210/msg00460.html"&gt;http://www.groupstudy.com/archives/ccielab/201210/msg00460.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;which stat once failover it will have a delay of 10sec.&lt;/P&gt;&lt;P&gt;also found the following link with the bug, hence I am trying to find some tweak on router level&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.gossamer-threads.com/lists/cisco/nsp/161609"&gt;http://www.gossamer-threads.com/lists/cisco/nsp/161609&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 17:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141067#M359796</guid>
      <dc:creator>Lance Wendel</dc:creator>
      <dc:date>2013-03-20T17:32:31Z</dc:date>
    </item>
    <item>
      <title>ASA HA Pair and OSPF with router</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141068#M359797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Lance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeahp,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see the same behavior after failover happens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the OSPF neighorship goes down?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 19:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-and-ospf-with-router/m-p/2141068#M359797</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T19:41:50Z</dc:date>
    </item>
  </channel>
</rss>

