<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Failover issue. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112490#M393646</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i assume that is the output from the secondary unit, correct? do you also have the output from the primary unit? how do you connect the failover link between those two asa? do you get any messages from enabling the debug command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Dec 2012 10:20:04 GMT</pubDate>
    <dc:creator>Rudy Sanjoko</dc:creator>
    <dc:date>2012-12-28T10:20:04Z</dc:date>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112487#M393643</link>
      <description>&lt;P&gt;we have cisco asa 5550 firewall running on ios 8.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have add two new interface on firewall,&amp;nbsp; but it show failled on sh failover output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last Failover at: 22:50:59 IST Dec 4 2012&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This host: Secondary - Active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 2043566 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 0: ASA5550 hw/sw rev (2.0/8.2(2)) status (Up Sys)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface DMZ-Inside (10.132.x.x/fe80::226:bff:fe43:6672): Normal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside (180.x.x.x): Normal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management (192.168.1.1): No Link (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface IPVSIX (0.0.0.0/fe80::225:84ff:fefd:1d7): Normal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface TATA-INTERNET (115.x.x.226): Normal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 1: ASA-SSM-4GE-INC hw/sw rev (1.0/1.0(0)10) status (Up)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Other host: Primary - Failed&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 0 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 0: ASA5550 hw/sw rev (2.0/8.2(2)) status (Up Sys)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface DMZ-Inside (10.132.x.x/fe80::226:bff:fe43:6686): Normal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface outside (180.x.x.x) Normal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface management (0.0.0.0): Normal (Not-Monitored)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface IPVSIX (0.0.0.0/fe80::225:84ff:fefd:1ff): Failed (Waiting)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface TATA-INTERNET (115.x.x.227): Normal (Waiting)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot 1: ASA-SSM-4GE-INC hw/sw rev (1.0/1.0(0)10) status (Up)&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Link : Unconfigured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bhupendra Jain&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112487#M393643</guid>
      <dc:creator>bhupendrajain</dc:creator>
      <dc:date>2019-03-12T00:41:45Z</dc:date>
    </item>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112488#M393644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the above output, it tells me that the failover link is uncofigured also i can see that both asa have the same ios version, interface and model. it would be best if you can share the config of the failover on both sides and enable debugging for failover, below are some usefull commands that can be use to troubleshoot the failover on asa,&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;show failover&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;show failover group&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;show monitor-interface&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;show running-config failover&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;debug fover&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 09:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112488#M393644</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2012-12-28T09:27:51Z</dc:date>
    </item>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112489#M393645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi rudy &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the above output is for show failover command and show failover group, show monitor-interface commnad is not working&lt;/P&gt;&lt;P&gt;The Output of Show running- config is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit secondary&lt;/P&gt;&lt;P&gt;failover lan interface Failover GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover interface ip Failover 1.1.1.1 255.255.255.252 standby 1.1.1.2&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 10:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112489#M393645</guid>
      <dc:creator>bhupendrajain</dc:creator>
      <dc:date>2012-12-28T10:09:32Z</dc:date>
    </item>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112490#M393646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i assume that is the output from the secondary unit, correct? do you also have the output from the primary unit? how do you connect the failover link between those two asa? do you get any messages from enabling the debug command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 10:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112490#M393646</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2012-12-28T10:20:04Z</dc:date>
    </item>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112491#M393647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi rudy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both firewall is connected back to back with interface 0/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run failover output of primary unit, Presently primary unit is failed and secondry unit is active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface Failover GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover interface ip Failover 1.1.1.1 255.255.255.252 standby 1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we do not enable debug on firewall &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 10:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112491#M393647</guid>
      <dc:creator>bhupendrajain</dc:creator>
      <dc:date>2012-12-28T10:47:54Z</dc:date>
    </item>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112492#M393648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this is stupid questions, but just to confirm, have you enable&amp;nbsp; the failover? have you enable the interface for the failover on both&amp;nbsp; asa? can you give me the output from show failover state as well from&amp;nbsp; both asa?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 14:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112492#M393648</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2012-12-28T14:28:44Z</dc:date>
    </item>
    <item>
      <title>ASA Failover issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112493#M393649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At first glance it appears the IPVSIX interface is down on the Primary unit. &lt;SPAN style="font-size: 10pt;"&gt;Please confirm state via "show interface IPVSIX" on that unit.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;If it is up, it may be that the Secondary-Active unit cannot confirm it since the interface is IPv6 only and your failover interafce is not IPv6-enabled. If that is the case, try adding IPv6 addresses on the failover interfaces.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;"&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;If an interface has only IPv6 addresses configured on it, then the ASA uses IPv6 neighbor discovery instead of ARP to perform the health monitoring tests. For the broadcast ping test, the ASA uses the IPv6 all nodes address (FE02::1).&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1079057"&gt;Source&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 15:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-issue/m-p/2112493#M393649</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-12-28T15:26:53Z</dc:date>
    </item>
  </channel>
</rss>

