<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945004#M5187</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question during my project for ASA High Availability&lt;/P&gt;&lt;P&gt;Here's the topology :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/47581iA9C045D1D00EEC0F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Topology.JPG" alt="Topology.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Failover already working, but one point was not working .&lt;/P&gt;&lt;P&gt;So if we remove cable from ISP 1 (orange cable / A), the traffic didn't go through ISP 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if we shutdown manually connection of ASA - Switch Edge (Orange Cable / Point B) and automatically ASA Secondary Orange Cable will be shutdown due sync.. The traffic will working to ISP 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using 2 IP Route and SLA for the configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;route Outside3 0.0.0.0 0.0.0.0 123.231.x.x 1 track 1
route Outside 0.0.0.0 0.0.0.0 202.159.x.x 2

sla monitor 1
 type echo protocol ipIcmpEcho 123.231.x.x interface Outside3
sla monitor schedule 1 life forever start-time now

track 1 rtr 1 reachability&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea about this one? What I should to do for troubleshoot?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:36:49 GMT</pubDate>
    <dc:creator>M Rinaldy Aulia</dc:creator>
    <dc:date>2020-02-21T17:36:49Z</dc:date>
    <item>
      <title>ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945004#M5187</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question during my project for ASA High Availability&lt;/P&gt;&lt;P&gt;Here's the topology :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/47581iA9C045D1D00EEC0F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Topology.JPG" alt="Topology.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Failover already working, but one point was not working .&lt;/P&gt;&lt;P&gt;So if we remove cable from ISP 1 (orange cable / A), the traffic didn't go through ISP 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if we shutdown manually connection of ASA - Switch Edge (Orange Cable / Point B) and automatically ASA Secondary Orange Cable will be shutdown due sync.. The traffic will working to ISP 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using 2 IP Route and SLA for the configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;route Outside3 0.0.0.0 0.0.0.0 123.231.x.x 1 track 1
route Outside 0.0.0.0 0.0.0.0 202.159.x.x 2

sla monitor 1
 type echo protocol ipIcmpEcho 123.231.x.x interface Outside3
sla monitor schedule 1 life forever start-time now

track 1 rtr 1 reachability&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea about this one? What I should to do for troubleshoot?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945004#M5187</guid>
      <dc:creator>M Rinaldy Aulia</dc:creator>
      <dc:date>2020-02-21T17:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945010#M5188</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Try to make SLA timeout after some specific timing and packet drop as:&lt;/P&gt;
&lt;PRE&gt;sla monitor 1
 type echo protocol ipIcmpEcho 123.231.x.x interface Outside3&lt;BR /&gt;num-packets 3&lt;BR /&gt;frequency 3&lt;/PRE&gt;
&lt;P&gt;It will make SLA down after 9 to 12 seconds.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Second Question: Are your both WAN links under the failover monitor?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 04:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945010#M5188</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2019-10-22T04:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945015#M5189</link>
      <description>&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Hi Deepak,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;i will confirm again at my customer site, for the timeout.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;But As I remember, there’s already a timeout during the SLA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;because When I show route on ASA (if the cable from ISP1 - Switch Edge removed), route 0.0.0.0 0.0.0.0 already via ISP 2. And ASA can ping to internet&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;But from the user, we still can’t ping internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;So we need to shutdown first Interface from ASA - Switch Edge (Traffic to ISP1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;No i didnt put monitor on interface WAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;And the interface to ISP 1 and 2 doesnt have a standby IP, since availability&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 05:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945015#M5189</guid>
      <dc:creator>M Rinaldy Aulia</dc:creator>
      <dc:date>2019-10-22T05:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945033#M5190</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;As you said that you can ping the Internet via ISP2 but no internet on the client system then I am assuming some more testing as:&lt;/P&gt;
&lt;P&gt;1. Is DNS working during this downtime?&lt;/P&gt;
&lt;P&gt;2. Is Xlate table issue?&lt;/P&gt;
&lt;P&gt;3. Is the system failover happening after disconnecting the cable?&lt;/P&gt;
&lt;P&gt;4. Is routing table updating (as you can ping the internet using ISP2 so I don't think routing table issue? This may be due to SLA &amp;amp; tracker.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you check the above things and share running configuration with logs.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 06:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945033#M5190</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2019-10-22T06:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945121#M5191</link>
      <description>&lt;P&gt;Hi Deepak,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is DNS working during this downtime? I assuming the DNS working, but user no internet connection during ISP 1 Fail (without shutdown the interface). I only can ping the internet from ASA&lt;/P&gt;&lt;P&gt;2. Is Xlate table issue? I'm not yet touching this area.&lt;/P&gt;&lt;P&gt;3. Is the system failover happening after disconnecting the cable? No, failover not happening.&lt;/P&gt;&lt;P&gt;4. Is routing table updating (as you can ping the internet using ISP2 so I don't think routing table issue? This may be due to SLA &amp;amp; tracker // Yes, it's updating the 0.0.0.0 0.0.0.0 to ISP2&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you check the above things and share running configuration with logs.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 08:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945121#M5191</guid>
      <dc:creator>M Rinaldy Aulia</dc:creator>
      <dc:date>2019-10-22T08:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945122#M5192</link>
      <description>&lt;P&gt;Hi Deepak,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached the show run configuration&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 09:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-failover/m-p/3945122#M5192</guid>
      <dc:creator>M Rinaldy Aulia</dc:creator>
      <dc:date>2019-10-22T09:00:27Z</dc:date>
    </item>
  </channel>
</rss>

