<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA failover problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover-problem/m-p/489497#M427578</link>
    <description>&lt;P&gt;Hi! I have two ASA 5520 with AIP-SSM Module. I have configured stateful failover and I `ve got two questions. &lt;/P&gt;&lt;P&gt;1. When I power off the primary failover unit I loose contact with the firewall about 10 seconds,(I don`t think this is normal when you use virtual mac address)  and it is the same problem when I power off the secondary unit. I am not sure if I have configured virtual mac address correct. &lt;/P&gt;&lt;P&gt;2. Can the ip address at the AIP-SSM be the same (I have read  that they are NOT involved in the failover function) or do it have to be different addresses?&lt;/P&gt;&lt;P&gt;Does anyone know the answers to this I would be very grateful. Below is the failover configuration of the primary unit. The second unit was configured exactly the same apart from command &amp;#147;failover lan unit&amp;#148;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover_interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover mac address GigabitEthernet0/0 7889.7889.9990 7889.7889.9991&lt;/P&gt;&lt;P&gt;failover mac address GigabitEthernet0/2 7889.7889.8880 7889.7889.8881&lt;/P&gt;&lt;P&gt;failover mac address GigabitEthernet0/3 7889.7889.7770 7889.7889.7771&lt;/P&gt;&lt;P&gt;failover link failover_interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover interface ip failover_interface 172.29.20.1 255.255.255.0 standby 172.29.20.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:40:27 GMT</pubDate>
    <dc:creator>cisco7889</dc:creator>
    <dc:date>2020-02-21T08:40:27Z</dc:date>
    <item>
      <title>ASA failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-problem/m-p/489497#M427578</link>
      <description>&lt;P&gt;Hi! I have two ASA 5520 with AIP-SSM Module. I have configured stateful failover and I `ve got two questions. &lt;/P&gt;&lt;P&gt;1. When I power off the primary failover unit I loose contact with the firewall about 10 seconds,(I don`t think this is normal when you use virtual mac address)  and it is the same problem when I power off the secondary unit. I am not sure if I have configured virtual mac address correct. &lt;/P&gt;&lt;P&gt;2. Can the ip address at the AIP-SSM be the same (I have read  that they are NOT involved in the failover function) or do it have to be different addresses?&lt;/P&gt;&lt;P&gt;Does anyone know the answers to this I would be very grateful. Below is the failover configuration of the primary unit. The second unit was configured exactly the same apart from command &amp;#147;failover lan unit&amp;#148;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover_interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover mac address GigabitEthernet0/0 7889.7889.9990 7889.7889.9991&lt;/P&gt;&lt;P&gt;failover mac address GigabitEthernet0/2 7889.7889.8880 7889.7889.8881&lt;/P&gt;&lt;P&gt;failover mac address GigabitEthernet0/3 7889.7889.7770 7889.7889.7771&lt;/P&gt;&lt;P&gt;failover link failover_interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover interface ip failover_interface 172.29.20.1 255.255.255.0 standby 172.29.20.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-problem/m-p/489497#M427578</guid>
      <dc:creator>cisco7889</dc:creator>
      <dc:date>2020-02-21T08:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover-problem/m-p/489498#M427580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To log in to AIP SSM from ASA, follow these steps: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1 Log in to ASA. &lt;/P&gt;&lt;P&gt;If ASA is operating in multi-mode, use the change system command to get to the system level prompt before continuing. -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2 Session to AIP SSM: &lt;/P&gt;&lt;P&gt;asa# session 1&lt;/P&gt;&lt;P&gt;Step 3 Type your username and password at the login prompt: &lt;/P&gt;&lt;P&gt;The default username and password are both cisco. You are prompted to change them the first time you log in to AIP SSM. You must first enter the UNIX password, which is cisco. Then you must enter the new password twice. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jan 2006 21:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover-problem/m-p/489498#M427580</guid>
      <dc:creator>owillins</dc:creator>
      <dc:date>2006-01-31T21:19:42Z</dc:date>
    </item>
  </channel>
</rss>

