<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic interface failover issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191746#M359855</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't understand you you're trying to use HSRP between your router and switces. If you have l3 reachability (i.e. routing enabled between your asa/switches/router) just let eighp take care of redundancy. just don't see why you should use HSRP here, or maybe i'm missing something)). Maybe someone else can comment on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Mar 2013 07:07:12 GMT</pubDate>
    <dc:creator>Andrew Phirsov</dc:creator>
    <dc:date>2013-03-22T07:07:12Z</dc:date>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191741#M359850</link>
      <description>&lt;P&gt;hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a ASA 5550 firewall interface failover issue.&lt;/P&gt;&lt;P&gt;Please take a look at the attached file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I shut down the inside interface Gi 1/1 of the left firewall(Active firewall),&lt;/P&gt;&lt;P&gt;It failed to failover.&lt;/P&gt;&lt;P&gt;but when I shut down the Gi 1/12 of the Core 1 switch,&lt;/P&gt;&lt;P&gt;The firewall failover very well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed this guide but I was not able to failover.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/228489" rel="nofollow" target="_blank"&gt;https://supportforums.cisco.com/thread/228489&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can I configure so that when the Gi 1/1 or Gi 1/0 interface goes down,&lt;/P&gt;&lt;P&gt;it can failover ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate any help,&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;ASA config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;description STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;description LAN Failover Interface&lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0&lt;/P&gt;&lt;P&gt;media-type sfp&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 192.168.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;&lt;P&gt;media-type sfp&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.4.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P&gt;media-type sfp&lt;/P&gt;&lt;P&gt;nameif inside-backup&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.5.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/3&lt;/P&gt;&lt;P&gt;media-type sfp&lt;/P&gt;&lt;P&gt;nameif outside-backup&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 192.168.3.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group icmp-type AllowedICMP&lt;/P&gt;&lt;P&gt;icmp-object echo&lt;/P&gt;&lt;P&gt;icmp-object echo-reply&lt;/P&gt;&lt;P&gt;icmp-object traceroute&lt;/P&gt;&lt;P&gt;icmp-object unreachable&lt;/P&gt;&lt;P&gt;icmp-object time-exceeded&lt;/P&gt;&lt;P&gt;access-list EXEMPT extended permit ip 192.168.4.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list EXEMPT extended permit ip 10.1.0.0 255.255.0.0 any&lt;/P&gt;&lt;P&gt;access-list EXEMPT extended permit ip 192.168.5.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list no-nat extended permit ip 10.1.0.0 255.255.0.0 host 0.0.0.0&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any object-group AllowedICMP&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip host 192.168.2.253 any&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 192.168.2.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;…&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit secondary&lt;/P&gt;&lt;P&gt;failover lan interface fobasic Management0/0&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover link fostate GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip fobasic 192.168.200.1 255.255.255.0 standby 192.168.200.2&lt;/P&gt;&lt;P&gt;failover interface ip fostate 192.168.201.1 255.255.255.0 standby 192.168.201.2&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any unreachable outside&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (outside-backup) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list no-nat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group outside_access_in out interface outside&lt;/P&gt;&lt;P&gt;access-group EXEMPT in interface inside&lt;/P&gt;&lt;P&gt;access-group EXEMPT out interface inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router eigrp 10&lt;/P&gt;&lt;P&gt;no auto-summary&lt;/P&gt;&lt;P&gt;network 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network 192.168.4.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network 192.168.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;redistribute static&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.2.254 1&lt;/P&gt;&lt;P&gt;……&lt;/P&gt;&lt;P&gt;http 10.1.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 1 rtr 123 reachability&lt;/P&gt;&lt;P&gt;……..&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;dhcpd dns x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum client auto&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect esmtp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;inspect ip-options&lt;/P&gt;&lt;P&gt;inspect icmp&lt;/P&gt;&lt;P&gt;inspect icmp error&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;…..&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191741#M359850</guid>
      <dc:creator>wasahongNYC</dc:creator>
      <dc:date>2019-03-12T01:16:28Z</dc:date>
    </item>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191742#M359851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's normal behavior))). When you do shutdown of gi1/1 on active ASA, you automatically shutdownn the same interface on the standby appliance. So the normal command syncronization is happenning and no failover occurs.&lt;/P&gt;&lt;P&gt;But when you shutdown interface of a switch, interface of active ASA gets marked as &lt;EM&gt;failed, &lt;/EM&gt;and failover happens. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 16:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191742#M359851</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-03-19T16:47:33Z</dc:date>
    </item>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191743#M359852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for your instant reply.&lt;/P&gt;&lt;P&gt;It do help me a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, my goal is to test the firewall failover situation.&lt;/P&gt;&lt;P&gt;since I hope the left ASA( either device itself or any interface ) goes down,&lt;/P&gt;&lt;P&gt;then the right ASA can take over very well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in this case, on top of 1) unplug the cable between Core 1 switch and the left ASA&lt;/P&gt;&lt;P&gt;2) unplug the left ASA power&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any way that I can test Gi 1/1 of left ASA failover ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 17:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191743#M359852</guid>
      <dc:creator>wasahongNYC</dc:creator>
      <dc:date>2013-03-19T17:20:23Z</dc:date>
    </item>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191744#M359853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you unplug the cable between core 1 and left ASA&amp;nbsp; the failover will occur, as long as monitoring of gi1/1 enabled on ASA (wich it is by default).&amp;nbsp; And unplugging that caple - you're testing gi1/1, as u asked on the last sentence. If you unplug left ASA power, failover also will happen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 07:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191744#M359853</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-03-20T07:53:44Z</dc:date>
    </item>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191745#M359854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again for your reply.&lt;/P&gt;&lt;P&gt;May I have one more question ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring the failover for the two interfaces between router and left switch.&lt;/P&gt;&lt;P&gt;what I want is when the left switch's outside interface( connecting to router ) shut down,&lt;/P&gt;&lt;P&gt;then the inbound traffice should go this way, router -&amp;gt; right switch -&amp;gt; left ASA&lt;/P&gt;&lt;P&gt;outbound as well&lt;/P&gt;&lt;P&gt;and after I shut down the switch's interface (connecting to router),&lt;/P&gt;&lt;P&gt;connectivity situation,&lt;/P&gt;&lt;P&gt;host can ping router's backup interface(192.168.3.253) and 192.168.3.253 can ping 4.2.2.2,&lt;/P&gt;&lt;P&gt;while host can NOT ping 4.2.2.2&lt;/P&gt;&lt;P&gt;also, 192.168.3.253 can ping left firewall's 1/3 interface (192.168.3.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think there is something wrong with my firewall configuration or router static route configuration.&lt;/P&gt;&lt;P&gt;so please help me when you are available.&lt;/P&gt;&lt;P&gt;This is my first time to configure IP SLA for backup static route. &lt;/P&gt;&lt;P&gt;correct me if I am wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router config :&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;…………..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;description ISP circuit order 1-111111111111&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip address X.X.X.X 255.255.255.248&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip accounting output-packets &lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip nat outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip nat enable&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no ip virtual-reassembly&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;duplex full&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;speed 1000&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;media-type sfp&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no negotiation auto&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;description uplink to main-1 interface g 1/0/12&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip address 192.168.2.253 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip accounting output-packets&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip nat inside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip nat enable&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no ip virtual-reassembly&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;duplex full&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;speed 1000&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;media-type sfp&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no negotiation auto&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;standby 2 ip 192.168.2.254&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;standby 2 priority 110&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;standby 2 preempt&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip address 192.168.3.253 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no ip redirects&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;duplex full&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;speed 1000&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;negotiation auto&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;standby 3 ip 192.168.3.254&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;standby 3 priority 110&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;standby 3 preempt&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;router eigrp 10&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;redistribute static&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;passive-interface GigabitEthernet0/0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;network 192.168.2.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;network 192.168.3.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no auto-summary&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip forward-protocol nd&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip route 0.0.0.0 0.0.0.0 X.X.X.X&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip route 10.1.0.0 255.255.0.0 192.168.2.1&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip route 10.1.20.0 255.255.255.0 192.168.2.13&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;no ip http server&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip dns server view-group aaaaaaa&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip dns server&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip nat pool mypool X.X.X.X X.X.X.X netmask 255.255.255.252&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ip nat inside source list 1 pool mypool overload&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;logging alarm informational&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;access-list 1 permit 192.168.2.0 0.0.0.255&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;access-list 1 permit 192.168.3.0 0.0.0.255&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;access-list 1 permit 10.1.33.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;control-plane&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;gatekeeper&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;shutdown&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ASA config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;.....&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;description STATE Failover Interface&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface Management0/0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;description LAN Failover Interface&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;management-only&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface GigabitEthernet1/0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;media-type sfp&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;nameif outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;security-level 0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ip address 192.168.2.1 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface GigabitEthernet1/1&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;media-type sfp&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;nameif inside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;security-level 100&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ip address 192.168.4.1 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;media-type sfp&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;nameif inside-backup&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;security-level 100&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ip address 192.168.5.1 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;interface GigabitEthernet1/3&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;media-type sfp&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;nameif outside-backup&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;security-level 0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ip address 192.168.3.1 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;ftp mode passive&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;object-group icmp-type AllowedICMP&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp-object echo&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp-object echo-reply&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp-object traceroute&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp-object unreachable&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp-object time-exceeded&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list EXEMPT extended permit ip 192.168.4.0 255.255.255.0 any&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list EXEMPT extended permit ip 10.1.0.0 255.255.0.0 any&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list EXEMPT extended permit ip 192.168.5.0 255.255.255.0 any&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list no-nat extended permit ip 10.1.0.0 255.255.0.0 host 0.0.0.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list outside_access_in extended permit icmp any any object-group AllowedICMP&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list outside_access_in extended permit ip host 192.168.2.253 any&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list outside_access_in extended permit ip 192.168.2.0 255.255.255.0 any&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list outside_access_in extended permit ip host 192.168.3.253 any&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-list outside_access_in extended permit ip 192.168.3.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;…&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover lan unit secondary&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover lan interface fobasic Management0/0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover key *****&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover link fostate GigabitEthernet0/3&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover interface ip fobasic 192.168.200.1 255.255.255.0 standby 192.168.200.2&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;failover interface ip fostate 192.168.201.1 255.255.255.0 standby 192.168.201.2&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp permit any unreachable outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp permit any echo-reply outside-backup&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;icmp permit any unreachable outside-backup&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;no asdm history enable&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;arp timeout 14400&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;global (outside) 1 interface&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;global (outside-backup) 1 interface&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;nat (inside) 0 access-list no-nat&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-group outside_access_in out interface outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-group outside_access_in in interface outside-backup&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-group outside_access_in out interface outside-backup&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-group EXEMPT in interface inside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;access-group EXEMPT out interface inside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;router eigrp 10&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;no auto-summary&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;network 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;network 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;network 192.168.4.0 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;network 192.168.5.0 255.255.255.0&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;redistribute static&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;route outside 0.0.0.0 0.0.0.0 192.168.2.253 1 track 20&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;route outside 0.0.0.0 0.0.0.0 192.168.3.253 22&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;……&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;http 10.1.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;no snmp-server location&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;no snmp-server contact&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;track 1 rtr 123 reachability&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;……..&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;sla monitor 2&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;type echo protocol ipIcmpEcho 192.168.2.253 interface outside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;sla monitor schedule 2 life forever start-time now&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;track 20 rtr 2 reachability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;management-access inside&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;dhcpd dns x.x.x.x&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;threat-detection basic-threat&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;webvpn&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;class-map inspection_default&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;match default-inspection-traffic&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;!&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;…..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 00:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191745#M359854</guid>
      <dc:creator>wasahongNYC</dc:creator>
      <dc:date>2013-03-22T00:55:27Z</dc:date>
    </item>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191746#M359855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't understand you you're trying to use HSRP between your router and switces. If you have l3 reachability (i.e. routing enabled between your asa/switches/router) just let eighp take care of redundancy. just don't see why you should use HSRP here, or maybe i'm missing something)). Maybe someone else can comment on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 07:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191746#M359855</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-03-22T07:07:12Z</dc:date>
    </item>
    <item>
      <title>interface failover issue</title>
      <link>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191747#M359856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;okay, I see.&lt;/P&gt;&lt;P&gt;I think at this moment I do NOT need the HSRP configuration.&lt;/P&gt;&lt;P&gt;do you have any idea about the ASA routing configuration ?&lt;/P&gt;&lt;P&gt;since now the backup interface of router is not able to ping inside host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 12:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-failover-issue/m-p/2191747#M359856</guid>
      <dc:creator>wasahongNYC</dc:creator>
      <dc:date>2013-03-22T12:44:16Z</dc:date>
    </item>
  </channel>
</rss>

