<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA and EIGRP Flapping in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939810#M458573</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been having an annoying issue for the past few weeks with my ASA setup. We are using the ASA as our Remote Access Gateway and originally had it setup in a Active/Standby failover configuration using 2 x 5520 ASA's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original setup of the devices was that the 2 x ASA were setup in a failover configuration, with both of them connecting back to the internal network via a 6500 device. Because of using failover I created a VLAN on the 6500 and put the two ports that connect the ASA's into that VLAN. I then configured the VLAN interface to be the EIGRP interface for the neighbour relationship to the ASA's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I am seeing is that the EIGRP neighbour relationship between the Active ASA and the 6500 keeps flapping. It occurs abour 4-5 times every day at randmon intervals. Sometimes the neighbour relationship will stay up for 6-7 hours, other times it flaps every 1-2 hours. I initially thought it was due to the failover configuration so I removed one of the ASA's and removed all of the failover configuration, but the EIGRP neighbour flapping problem still exisits. The error log's on the 6500 are:&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:12:01: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is down: holding time expired&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: Neighbor x.x.x.x went down on Vlan97&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: New peer x.x.x.x&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:12:07: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is up: new adjacency&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:12:07: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is down: Interface Goodbye received&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: Neighbor x.x.x.x went down on Vlan97&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: New peer x.x.x.x&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:15:09: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is up: new adjacency&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The basic network configuration is like this:&lt;/P&gt;&lt;P&gt;outside----------ASA----inside-------\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (failover)&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6500 (via a VLAN)&lt;/P&gt;&lt;P&gt;outside----------ASA----inside-------/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since removing the failvoer configuration I am thinking it could be a physical cable problem? Would that make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Cameron &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS - I am running 8.4(2)18 on the ASA's.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:37:38 GMT</pubDate>
    <dc:creator>cammaher</dc:creator>
    <dc:date>2019-03-11T22:37:38Z</dc:date>
    <item>
      <title>ASA and EIGRP Flapping</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939810#M458573</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been having an annoying issue for the past few weeks with my ASA setup. We are using the ASA as our Remote Access Gateway and originally had it setup in a Active/Standby failover configuration using 2 x 5520 ASA's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original setup of the devices was that the 2 x ASA were setup in a failover configuration, with both of them connecting back to the internal network via a 6500 device. Because of using failover I created a VLAN on the 6500 and put the two ports that connect the ASA's into that VLAN. I then configured the VLAN interface to be the EIGRP interface for the neighbour relationship to the ASA's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I am seeing is that the EIGRP neighbour relationship between the Active ASA and the 6500 keeps flapping. It occurs abour 4-5 times every day at randmon intervals. Sometimes the neighbour relationship will stay up for 6-7 hours, other times it flaps every 1-2 hours. I initially thought it was due to the failover configuration so I removed one of the ASA's and removed all of the failover configuration, but the EIGRP neighbour flapping problem still exisits. The error log's on the 6500 are:&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:12:01: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is down: holding time expired&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: Neighbor x.x.x.x went down on Vlan97&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: New peer x.x.x.x&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:12:07: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is up: new adjacency&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:12:07: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is down: Interface Goodbye received&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: Neighbor x.x.x.x went down on Vlan97&lt;/P&gt;&lt;P&gt;30w1d: EIGRP: New peer x.x.x.x&lt;/P&gt;&lt;P&gt;Mar&amp;nbsp; 2 03:15:09: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor x.x.x.x (Vlan97) is up: new adjacency&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The basic network configuration is like this:&lt;/P&gt;&lt;P&gt;outside----------ASA----inside-------\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (failover)&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6500 (via a VLAN)&lt;/P&gt;&lt;P&gt;outside----------ASA----inside-------/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since removing the failvoer configuration I am thinking it could be a physical cable problem? Would that make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Cameron &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS - I am running 8.4(2)18 on the ASA's.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939810#M458573</guid>
      <dc:creator>cammaher</dc:creator>
      <dc:date>2019-03-11T22:37:38Z</dc:date>
    </item>
    <item>
      <title>ASA and EIGRP Flapping</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939811#M458574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you see any interface errors on the ASA,&lt;/P&gt;&lt;P&gt;What does the ASA's debug eigrp packets suggest&lt;/P&gt;&lt;P&gt;Do you see any interface going down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2012 10:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939811#M458574</guid>
      <dc:creator>svaish</dc:creator>
      <dc:date>2012-03-05T10:03:08Z</dc:date>
    </item>
    <item>
      <title>ASA and EIGRP Flapping</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939812#M458575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Svaish,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, there are no interface errors on the ASA, all the values in the counters appear normal. There aren't any interfaces going down either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm in the process of doing a debug on the ASA and will provide more info when I get it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Cameron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2012 22:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939812#M458575</guid>
      <dc:creator>cammaher</dc:creator>
      <dc:date>2012-03-05T22:39:11Z</dc:date>
    </item>
    <item>
      <title>ASA and EIGRP Flapping</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939813#M458576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Collecting debugs for EIGRP will be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 07:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939813#M458576</guid>
      <dc:creator>svaish</dc:creator>
      <dc:date>2012-03-06T07:16:40Z</dc:date>
    </item>
    <item>
      <title>ASA and EIGRP Flapping</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939814#M458577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We just experienced a simiar issue.&amp;nbsp; The VLANs we use are set to mtu 9216.&amp;nbsp; By removing and reapplying the mtu setting to the VLAN on the 6500, the flapping went away.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2012 13:24:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-eigrp-flapping/m-p/1939814#M458577</guid>
      <dc:creator>joseph.bernard</dc:creator>
      <dc:date>2012-06-04T13:24:04Z</dc:date>
    </item>
  </channel>
</rss>

