<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA active/active failover and IPS failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635854#M558823</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 asa 5520 firewalls including and 1 AIP-SSM-10 module in each of them. the configuration is set using active/active failover and context mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of them run individualy the IPS module. The IPS is configured using inline mode and fail-open option. However when one of the module fails and the state is changing from up to init or anything else making the IPS to fail then failover is detected and ASA consider it as failover and bounce context to the other unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS soft is 6.0(4) and ASA soft is 8.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked cisco doc and it is confusing to me. it says:&amp;nbsp; &lt;SPAN class="content"&gt;"The AIP-SSM does not participate in stateful failover if stateful failover is configured on the ASA failover pair." but it really does participate. Running is not really an option because of production network impact matter....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has one of you had the experience of such issue or confusing behavior;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:15:09 GMT</pubDate>
    <dc:creator>durale1789</dc:creator>
    <dc:date>2019-03-11T20:15:09Z</dc:date>
    <item>
      <title>ASA active/active failover and IPS failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635854#M558823</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 asa 5520 firewalls including and 1 AIP-SSM-10 module in each of them. the configuration is set using active/active failover and context mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of them run individualy the IPS module. The IPS is configured using inline mode and fail-open option. However when one of the module fails and the state is changing from up to init or anything else making the IPS to fail then failover is detected and ASA consider it as failover and bounce context to the other unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS soft is 6.0(4) and ASA soft is 8.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked cisco doc and it is confusing to me. it says:&amp;nbsp; &lt;SPAN class="content"&gt;"The AIP-SSM does not participate in stateful failover if stateful failover is configured on the ASA failover pair." but it really does participate. Running is not really an option because of production network impact matter....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has one of you had the experience of such issue or confusing behavior;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635854#M558823</guid>
      <dc:creator>durale1789</dc:creator>
      <dc:date>2019-03-11T20:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA active/active failover and IPS failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635855#M558825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This thread will answer your question: Yes, what you are seeing is expected behaviour: &lt;/SPAN&gt;&lt;A class="jive-link-thread-small" href="https://community.cisco.com/thread/224795"&gt;https://supportforums.cisco.com/thread/224795&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below, if the IPS fails then this causes a failover of the ASA&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1149492"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1149492&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to rate all posts that are helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 14:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635855#M558825</guid>
      <dc:creator>sean_evershed</dc:creator>
      <dc:date>2011-03-31T14:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA active/active failover and IPS failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635856#M558827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much it is the information i was looking for so long ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to disable ot change this behavior or the default timer ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 15:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-active-failover-and-ips-failure/m-p/1635856#M558827</guid>
      <dc:creator>durale1789</dc:creator>
      <dc:date>2011-03-31T15:33:02Z</dc:date>
    </item>
  </channel>
</rss>

