<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5540 Stateful Failover routing errors in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337463#M417716</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear it's working, that's the most important thing. I'm not trying to preach, but Cisco recommends not using cross-over cables for fail over. The devices can't always tell who the master should be and usually causes more issues than just a link down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Oct 2009 19:25:48 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2009-10-30T19:25:48Z</dc:date>
    <item>
      <title>ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337455#M417705</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have two 5540's setup in a failover scenario.  Doing both LAN Failover and State Failover.  **see attached**&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The LAN Failover is using 192.168.2.1 as the active and 192.168.2.2 as the standby, with subnet mask of /30.  On both devices LAN Failover is using G0/2 and there is a crossover cable connecting them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The State Failover is using 192.168.3.1 as the active and 192.168.3.2 as the standby, with subnet mask of /30.  With â&amp;#128;&amp;#156;enable HTTP replicationâ&amp;#128;&amp;#157; checked in ASDM.  On both devices State Failover is using G0/3 and there is a crossover cable connecting them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASDM syslog is logging errors every 10 seconds or so that say:&lt;/P&gt;&lt;P&gt;SOURCE IP: 192.168.3.1&lt;/P&gt;&lt;P&gt;DESTINATION IP: 192.168.3.2&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;â&amp;#128;&amp;#156;Routing failed to locate next hop for igrp from NP identity 192.168.3.1/0 to statefull:192.168.3.2/0â&amp;#128;&amp;#157;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA's are using static routes to talk back to the network, of those routes there are two and both are in the 10.x.x.x network.  No routing protocol is in use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure why these errors are spamming my syslog and would love to get rid of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337455#M417705</guid>
      <dc:creator>Eric Hansen</dc:creator>
      <dc:date>2020-02-21T11:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337456#M417706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the results of &lt;B&gt;show run failover&lt;/B&gt;? From the active ASA can you ping 192.168.3.1 &amp;amp; .2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 17:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337456#M417706</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-10-30T17:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337457#M417709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;act/sec/ASAUFirewall# show fail&lt;/P&gt;&lt;P&gt;Failover On &lt;/P&gt;&lt;P&gt;Failover unit Secondary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: fail GigabitEthernet0/2 (up)&lt;/P&gt;&lt;P&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 1 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 8.2(1), Mate 8.2(1)&lt;/P&gt;&lt;P&gt;Last Failover at: 16:35:59 UTC Oct 30 2009&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This host: Secondary - Active &lt;/P&gt;&lt;P&gt;                Active time: 6585 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5540 hw/sw rev (2.0/8.2(1)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface inside (10.0.0.2): Normal &lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): No Link (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface management (management): No Link (Not-Monitored)&lt;/P&gt;&lt;P&gt;                slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(1)E3) status (Up/Up)&lt;/P&gt;&lt;P&gt;                  IPS, 7.0(1)E3, Up&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other host: Primary - Standby Ready &lt;/P&gt;&lt;P&gt;                Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5540 hw/sw rev (2.0/8.2(1)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface inside (10.0.0.3): Normal &lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface management (0.0.0.0): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(1)E3) status (Up/Up)&lt;/P&gt;&lt;P&gt;                  IPS, 7.0(1)E3, Up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;/P&gt;&lt;P&gt;        Link : statefull GigabitEthernet0/3 (Failed)&lt;/P&gt;&lt;P&gt;        Stateful Obj    xmit       xerr       rcv        rerr      &lt;/P&gt;&lt;P&gt;        General         0          0          0          0         &lt;/P&gt;&lt;P&gt;        sys cmd         0          0          0          0         &lt;/P&gt;&lt;P&gt;        up time         0          0          0          0         &lt;/P&gt;&lt;P&gt;        RPC services    0          0          0          0         &lt;/P&gt;&lt;P&gt;        TCP conn        0          0          0          0         &lt;/P&gt;&lt;P&gt;        UDP conn        0          0          0          0         &lt;/P&gt;&lt;P&gt;        ARP tbl         0          0          0          0         &lt;/P&gt;&lt;P&gt;        Xlate_Timeout   0          0          0          0         &lt;/P&gt;&lt;P&gt;        VPN IKE upd     0          0          0          0         &lt;/P&gt;&lt;P&gt;        VPN IPSEC upd   0          0          0          0         &lt;/P&gt;&lt;P&gt;        VPN CTCP upd    0          0          0          0         &lt;/P&gt;&lt;P&gt;        VPN SDI upd     0          0          0          0         &lt;/P&gt;&lt;P&gt;        VPN DHCP upd    0          0          0          0         &lt;/P&gt;&lt;P&gt;        SIP Session     0          0          0          0         &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        Logical Update Queue Information&lt;/P&gt;&lt;P&gt;                        Cur     Max     Total&lt;/P&gt;&lt;P&gt;        Recv Q:         0       0       0&lt;/P&gt;&lt;P&gt;        Xmit Q:         0       0       0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 18:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337457#M417709</guid>
      <dc:creator>Eric Hansen</dc:creator>
      <dc:date>2009-10-30T18:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337458#M417711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;...and yes the secondary is currently active, only cause I booted the primary when I was trying to troubleshoot the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 18:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337458#M417711</guid>
      <dc:creator>Eric Hansen</dc:creator>
      <dc:date>2009-10-30T18:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337459#M417712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;B&gt;Link : statefull GigabitEthernet0/3 (Failed) &lt;/B&gt; Can you ping the failover IP's from the ASA? Do both show the above failed? Can you run a LAN-based failover?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 18:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337459#M417712</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-10-30T18:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337460#M417713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Crap, you asked for that and I completely didnt do it.  Sorry, here it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;act/sec/ASAUFirewall# ping 192.168.3.2                   &lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 192.168.3.2, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;No route to host 192.168.3.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the lan based fail, the primary ip is being monitored on the inside interface, so I shut the switchport the ASA is plugged into.  And as you can imagine while that port is in shut state I see this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;act/pri/ASAUFirewall# show fail&lt;/P&gt;&lt;P&gt;Failover On &lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: fail GigabitEthernet0/2 (up)&lt;/P&gt;&lt;P&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 1 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 8.2(1), Mate 8.2(1)&lt;/P&gt;&lt;P&gt;Last Failover at: 18:51:54 UTC Oct 30 2009&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This host: Primary - Active &lt;/P&gt;&lt;P&gt;                Active time: 102 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5540 hw/sw rev (2.0/8.2(1)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface inside (10.0.0.2): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): No Link (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface management (management): No Link (Not-Monitored)&lt;/P&gt;&lt;P&gt;                slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(1)E3) status (Up/Up)&lt;/P&gt;&lt;P&gt;                  IPS, 7.0(1)E3, Up&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other host: Secondary - Failed &lt;/P&gt;&lt;P&gt;                Active time: 8154 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5540 hw/sw rev (2.0/8.2(1)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface inside (10.0.0.3): No Link (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface management (0.0.0.0): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(1)E3) status (Up/Up)&lt;/P&gt;&lt;P&gt;                  IPS, 7.0(1)E3, Up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then I no shut the interface, now connecting the standby shows ready...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;act/pri/ASAUFirewall# show fail&lt;/P&gt;&lt;P&gt;Failover On &lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: fail GigabitEthernet0/2 (up)&lt;/P&gt;&lt;P&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 1 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 8.2(1), Mate 8.2(1)&lt;/P&gt;&lt;P&gt;Last Failover at: 18:51:54 UTC Oct 30 2009&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This host: Primary - Active &lt;/P&gt;&lt;P&gt;                Active time: 259 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5540 hw/sw rev (2.0/8.2(1)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface inside (10.0.0.2): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): No Link (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface management (management): No Link (Not-Monitored)&lt;/P&gt;&lt;P&gt;                slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(1)E3) status (Up/Up)&lt;/P&gt;&lt;P&gt;                  IPS, 7.0(1)E3, Up&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other host: Secondary - Standby Ready &lt;/P&gt;&lt;P&gt;                Active time: 8154 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5540 hw/sw rev (2.0/8.2(1)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface inside (10.0.0.3): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface management (0.0.0.0): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(1)E3) status (Up/Up)&lt;/P&gt;&lt;P&gt;                  IPS, 7.0(1)E3, Up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;e-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**also checked the show asp table routing and both 192.168.2.1 and 192.168.3.1 are in there as "identity" but no specific routes for either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe a bad cable?  aww wouldnt that be a kicker.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 19:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337460#M417713</guid>
      <dc:creator>Eric Hansen</dc:creator>
      <dc:date>2009-10-30T19:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337461#M417714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was thinking it could be a bad cable! Does the physical failover interface show down? Can you swap the cable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 19:08:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337461#M417714</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-10-30T19:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337462#M417715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I should have remember the rule "always check layer 1 first".  It was the cable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The odd thing is the interfaces on g0/3 showed link, showed activity, and showed up.  I just swapped the cable and bounced both devices and now the routing errors are gone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;act/pri/ASAUFirewall# ping 192.168.3.2&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 192.168.3.2, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for working through it with me, sorry to waste your time on a "physical" problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 19:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337462#M417715</guid>
      <dc:creator>Eric Hansen</dc:creator>
      <dc:date>2009-10-30T19:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 Stateful Failover routing errors</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337463#M417716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear it's working, that's the most important thing. I'm not trying to preach, but Cisco recommends not using cross-over cables for fail over. The devices can't always tell who the master should be and usually causes more issues than just a link down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 19:25:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-stateful-failover-routing-errors/m-p/1337463#M417716</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-10-30T19:25:48Z</dc:date>
    </item>
  </channel>
</rss>

