<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failover interface failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130886#M394872</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How is the HA configured? Straight through cable directly or using a switch in between? Can you also post a sanitized version of your failover configs from both primary and standby?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Nov 2012 16:35:53 GMT</pubDate>
    <dc:creator>Jack Leung</dc:creator>
    <dc:date>2012-11-30T16:35:53Z</dc:date>
    <item>
      <title>Failover interface failed</title>
      <link>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130884#M394869</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; I have 2 ASA 5520 firewall configured with HA(Failover). but some time my primary firewall goes down standby firewall doesnt come active. i found below log from primary firewall..what is the reason &amp;amp; what is the mining of reason code of 4...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Nov 30 2012 14:07:47: %ASA-1-105002: (ASA) Enabling failover.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Nov 30 2012 14:08:43: %ASA-1-105043: (Primary) Failover interface failed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Nov 30 2012 14:08:56: %ASA-1-103001: (Primary) No response from other firewall (reason code = 4).&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After i hard reboot my standby firewall below log had been generated..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #00ff00;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #00ff00;"&gt;&lt;STRONG&gt;Nov 30 2012 15:51:57: %ASA-1-105042: (Primary) Failover interface OK&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #00ff00;"&gt;&lt;STRONG&gt;Nov 30 2012 15:52:02: %ASA-1-709003: (Primary) Beginning configuration replication: Send to mate.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #00ff00;"&gt;&lt;STRONG&gt;Nov 30 2012 15:52:15: %ASA-1-709004: (Primary) End Configuration Replication (ACT) &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please assist....&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Suhas&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130884#M394869</guid>
      <dc:creator>suhas_syndrome</dc:creator>
      <dc:date>2019-03-12T00:30:46Z</dc:date>
    </item>
    <item>
      <title>Failover interface failed</title>
      <link>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130885#M394870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The explanation for that can be found in the ASAs syslog messages document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;H3&gt; 103001 &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;A name="wp4768590"&gt;&lt;/A&gt;Error Message&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-1-103001: (Primary) No response from other firewall (reason 
code = code).
&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt; &lt;A name="wp4768592"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Explanation&amp;nbsp;&amp;nbsp;&amp;nbsp; This is a failover message, which is displayed if the primary unit is unable to&amp;nbsp; communicate with the secondary unit over the failover cable. (Primary) can also be listed as&amp;nbsp; (Secondary). for the secondary unit. &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4768599"&gt;Table 1-2&lt;/A&gt; lists the reason codes and the descriptions to&amp;nbsp; determine why the failover occurred. &lt;/P&gt;
&lt;P&gt; &lt;A name="wp4768618"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;DIV align="left"&gt;
&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp4768599table4768596" width="80%"&gt;
&lt;CAPTION&gt;&lt;A name="wp4768599"&gt;&lt;/A&gt;
&lt;P&gt; Table 1-2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Reason Codes &lt;/P&gt;
&lt;/CAPTION&gt; 
&lt;TBODY&gt;
&lt;TR align="left" valign="bottom"&gt;
&lt;TH scope="col"&gt;&lt;A name="wp4768603"&gt;&lt;/A&gt;
&lt;DIV&gt; Reason Code &lt;/DIV&gt;
&lt;/TH&gt; &lt;TH scope="col"&gt;&lt;A name="wp4768605"&gt;&lt;/A&gt;
&lt;DIV&gt; Description &lt;/DIV&gt;
&lt;/TH&gt; 
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD&gt;&lt;A name="wp4768607"&gt;&lt;/A&gt;
&lt;P&gt; 1 &lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A name="wp4768609"&gt;&lt;/A&gt;
&lt;P&gt; The local unit is not receiving the hello packet on the failover LAN&amp;nbsp; interface when LAN failover occurs or on the serial failover cable when&amp;nbsp; serial failover occurs, and declares that the peer is down. &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD&gt;&lt;A name="wp4768611"&gt;&lt;/A&gt;
&lt;P&gt; 2 &lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A name="wp4768613"&gt;&lt;/A&gt;
&lt;P&gt; An interface did not pass one of the four failover tests, which are as&amp;nbsp; follows: 1) Link Up, 2) Monitor for Network Traffic, 3) ARP, and 4)&amp;nbsp; Broadcast Ping. &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD&gt;&lt;A name="wp4768615"&gt;&lt;/A&gt;
&lt;P&gt; 3 &lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A name="wp4768617"&gt;&lt;/A&gt;
&lt;P&gt; No proper ACK for 15+ seconds after a command was sent on the serial cable. &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD&gt;&lt;A name="wp5239695"&gt;&lt;/A&gt;
&lt;P&gt; 4 &lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A name="wp5239803"&gt;&lt;/A&gt;
&lt;P&gt; The local unit is not receiving the hello packet on the failover LAN and&amp;nbsp; other data interfaces and it is declaring that the peer is down. &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD&gt;&lt;A name="wp5239691"&gt;&lt;/A&gt;
&lt;P&gt; 5 &lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A name="wp5239693"&gt;&lt;/A&gt;
&lt;P&gt; The failover LAN interface is down, and other data interfaces are not&amp;nbsp; responding to additional interface testing. In addition, the local unit&amp;nbsp; is declaring that the peer is down. &lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt; &lt;A name="wp4768619"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Recommended Action&amp;nbsp;&amp;nbsp;&amp;nbsp; Verify that the failover cable is connected correctly and both units have the&amp;nbsp; same hardware, software, and configuration. If the problem persists, contact the Cisco TAC. &lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that the Primary ASA loses all connectivity to the Secondary ASA (looking at the log messages). Judging by the above Cisco description it would mean the Primary ASA isnt getting Failover Hellos through any of the monitored interfaces which again would make it seem like the Secondary Firewall is expriencing some problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 16:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130885#M394870</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-30T16:33:26Z</dc:date>
    </item>
    <item>
      <title>Failover interface failed</title>
      <link>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130886#M394872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How is the HA configured? Straight through cable directly or using a switch in between? Can you also post a sanitized version of your failover configs from both primary and standby?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 16:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-interface-failed/m-p/2130886#M394872</guid>
      <dc:creator>Jack Leung</dc:creator>
      <dc:date>2012-11-30T16:35:53Z</dc:date>
    </item>
  </channel>
</rss>

