<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA – Line Protocol status and Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602770#M593601</link>
    <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;I am looking for some confirmation on the conditions that will produce ASA failover in an Active/Standby configuration.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Primarily, what changes in the Line Protocol status of the monitored interface on the Active ASA will force a failover to the Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;In the attached diagram I have 2 ASAs connected to 2 Routers&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;My questions are as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;If the Primary Router loses power and/or fails, will the Primary Active ASA failover to the Secondary Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;If the cable is unplugged from the FE1 port on the Primary router, will the Primary Active ASA failover to the Secondary Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;If the FE1 port on the Primary Router fails, will the Primary Active ASA failover to the Secondary Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Thank you for your assistance.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:38:26 GMT</pubDate>
    <dc:creator>Cody Ridge</dc:creator>
    <dc:date>2019-03-11T19:38:26Z</dc:date>
    <item>
      <title>ASA – Line Protocol status and Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602770#M593601</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;I am looking for some confirmation on the conditions that will produce ASA failover in an Active/Standby configuration.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Primarily, what changes in the Line Protocol status of the monitored interface on the Active ASA will force a failover to the Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;In the attached diagram I have 2 ASAs connected to 2 Routers&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;My questions are as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;If the Primary Router loses power and/or fails, will the Primary Active ASA failover to the Secondary Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;If the cable is unplugged from the FE1 port on the Primary router, will the Primary Active ASA failover to the Secondary Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;If the FE1 port on the Primary Router fails, will the Primary Active ASA failover to the Secondary Standby ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Thank you for your assistance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:38:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602770#M593601</guid>
      <dc:creator>Cody Ridge</dc:creator>
      <dc:date>2019-03-11T19:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA – Line Protocol status and Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602771#M593603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA failover uses keepalive between the ASA interfaces to failover from active to standby firewall.&lt;/P&gt;&lt;P&gt;It is actually monitoring the ASA interfaces, not the other device interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Base on your diagram, I am assuming that the ASA and the router fe1 interfaces are connected via switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your question:&lt;/P&gt;&lt;P&gt;1) If the primary router is down, the ASA will not failover to the standby firewall. As it is not monitoring the interfaces of other devices connected in the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If the router fe1 is connected to a switch, and if it's unplugged, no, the ASA will not failover from active to standby. Same reason as above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Similarly, if the router fe1 fails, again, the ASA will not failover for the same reason as above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answer to all your questions is NO. This is assuming that they are all connected to a switch, not directly connected to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA failover will be triggered if the ASA is down, if the ASA interface is unplugged from the firewall and if the ASA interface fails and it can no longer receive or ack on the failover keepalive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 16:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602771#M593603</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-21T16:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA – Line Protocol status and Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602772#M593608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The primary ASA and primary Router will actually be directly connected. &lt;/P&gt;&lt;P&gt;No physical switches will be between the ASAs and routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;o1 int on primary ASA will connect to FE1 switchport on the primary router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once connected the interface status on the primary ASA will be "Interface Ethernet0 "xx", is up, line protocol is up"&lt;/P&gt;&lt;P&gt;If the cable is unplugged from FE1 on the primary router, will the ASA interface status change to "line protocol is down"?&lt;/P&gt;&lt;P&gt;If the interface line protocol is down, will the primary ASA failover to the secondary ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 17:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602772#M593608</guid>
      <dc:creator>Cody Ridge</dc:creator>
      <dc:date>2011-01-21T17:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA – Line Protocol status and Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602773#M593610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the router fails, if they are directly connected to the ASA, it should show that the ASA interface which is connected to the router is also failing, hence, the failover will take place.&lt;/P&gt;&lt;P&gt;If the router interface is unplugged and down, and if they are directly connected, it will also show that the ASA line protocol is down, hence triggers the failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is how ASA is checking the interface failover:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1079057"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1079057&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Jan 2011 17:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-line-protocol-status-and-failover/m-p/1602773#M593610</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-22T17:24:51Z</dc:date>
    </item>
  </channel>
</rss>

