<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with Active/Standby Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-active-standby-failover/m-p/3808643#M6785</link>
    <description>&lt;P&gt;Hello&amp;nbsp; all&lt;/P&gt;&lt;P&gt;i using ASAv (ovf ) into Vmware workstation for practicing ASA , i think my problem cause because of ASA&lt;STRONG&gt;v&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i review so many times but i can't simulate in Gns3 i prefer to ask&amp;nbsp; does it really happen due to using ASA&lt;STRONG&gt;v&lt;/STRONG&gt; or there is other problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i config two ASA completely for active/standby fail over they act perfectly without any problem&amp;nbsp;&lt;/P&gt;&lt;P&gt;but i connect one Lan User (Vmnet 15) and Give inside of ASA IP&lt;/P&gt;&lt;P&gt;while ASA(primary-Active) is active i can Do NAT and Lan user works without any problems&lt;/P&gt;&lt;P&gt;but while i change active ASA to standby then nothing happen from Lan user(Request time out)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'm sure no problem in ASA configuring(both : primary and secondary unit)&lt;/P&gt;&lt;P&gt;but why first primary asa changed to standby Inside Lan not possible to do NAT or ping any interfaces?&lt;/P&gt;&lt;P&gt;interfaces i mean (primary,secondary,outside,)anythings not possible&lt;/P&gt;&lt;P&gt;but if i changed a first asa to active everythings work fine!!!&lt;/P&gt;&lt;P&gt;do you thin this problem happens because of ASA&lt;STRONG&gt;v&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA1---&amp;gt;inside(vmnet 15)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA2---&amp;gt;inside(vmnet 15)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;int gi0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nameif INSIDE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip add 10.1.1.110 255.255.255.0 standby 10.1.1.220&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no shut&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;int gi0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no shut&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;all configuration replicated&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;but problem is if i reload or shutdown Active ASA&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Inside Lan user unable to communicate&amp;nbsp;with Secondary ASA in spite of ASA2 now has exact same ip add like ASA1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Default Gateway of Inside Lan User : 10.1.1.110&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;i enable icmp inspection&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my NAT configuration on Active ASA is:&lt;/P&gt;&lt;P&gt;object net inside_pool&lt;/P&gt;&lt;P&gt;subnet 10.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object net outside_pool&lt;/P&gt;&lt;P&gt;range 192.168.28.99 192.168.28.102&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object net inside_pool&lt;/P&gt;&lt;P&gt;nat (inside,outside) Dynamic outside_pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and one thing .... when ASA2 becomes active from it i cant ping any where :10.1.1.220(standby)or inside....&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:51:23 GMT</pubDate>
    <dc:creator>cisc0.ameer</dc:creator>
    <dc:date>2020-02-21T16:51:23Z</dc:date>
    <item>
      <title>Problem with Active/Standby Failover</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-active-standby-failover/m-p/3808643#M6785</link>
      <description>&lt;P&gt;Hello&amp;nbsp; all&lt;/P&gt;&lt;P&gt;i using ASAv (ovf ) into Vmware workstation for practicing ASA , i think my problem cause because of ASA&lt;STRONG&gt;v&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i review so many times but i can't simulate in Gns3 i prefer to ask&amp;nbsp; does it really happen due to using ASA&lt;STRONG&gt;v&lt;/STRONG&gt; or there is other problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i config two ASA completely for active/standby fail over they act perfectly without any problem&amp;nbsp;&lt;/P&gt;&lt;P&gt;but i connect one Lan User (Vmnet 15) and Give inside of ASA IP&lt;/P&gt;&lt;P&gt;while ASA(primary-Active) is active i can Do NAT and Lan user works without any problems&lt;/P&gt;&lt;P&gt;but while i change active ASA to standby then nothing happen from Lan user(Request time out)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'm sure no problem in ASA configuring(both : primary and secondary unit)&lt;/P&gt;&lt;P&gt;but why first primary asa changed to standby Inside Lan not possible to do NAT or ping any interfaces?&lt;/P&gt;&lt;P&gt;interfaces i mean (primary,secondary,outside,)anythings not possible&lt;/P&gt;&lt;P&gt;but if i changed a first asa to active everythings work fine!!!&lt;/P&gt;&lt;P&gt;do you thin this problem happens because of ASA&lt;STRONG&gt;v&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA1---&amp;gt;inside(vmnet 15)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA2---&amp;gt;inside(vmnet 15)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;int gi0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nameif INSIDE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip add 10.1.1.110 255.255.255.0 standby 10.1.1.220&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no shut&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;int gi0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no shut&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;all configuration replicated&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;but problem is if i reload or shutdown Active ASA&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Inside Lan user unable to communicate&amp;nbsp;with Secondary ASA in spite of ASA2 now has exact same ip add like ASA1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Default Gateway of Inside Lan User : 10.1.1.110&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;i enable icmp inspection&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my NAT configuration on Active ASA is:&lt;/P&gt;&lt;P&gt;object net inside_pool&lt;/P&gt;&lt;P&gt;subnet 10.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object net outside_pool&lt;/P&gt;&lt;P&gt;range 192.168.28.99 192.168.28.102&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object net inside_pool&lt;/P&gt;&lt;P&gt;nat (inside,outside) Dynamic outside_pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and one thing .... when ASA2 becomes active from it i cant ping any where :10.1.1.220(standby)or inside....&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-active-standby-failover/m-p/3808643#M6785</guid>
      <dc:creator>cisc0.ameer</dc:creator>
      <dc:date>2020-02-21T16:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Active/Standby Failover</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-active-standby-failover/m-p/3808650#M6788</link>
      <description>hello again&lt;BR /&gt;i find what is My problem&lt;BR /&gt;but now i reach more closely to that reason i mentioned&lt;BR /&gt;this problem cause due to using ASAv&lt;BR /&gt;but i'm not sure why!!! because [Inside Lan] and ASA1 (primary active) and ASA2(secondary Stndby) all three use Vmnet 15 for inside connectivity&lt;BR /&gt;and all Vmnet in workstation i put in order&lt;BR /&gt;for example inside is first&lt;BR /&gt;outside is second&lt;BR /&gt;.........&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ASDM Real time monitoring showing me Below Alert :&lt;BR /&gt;&lt;BR /&gt;105008&lt;BR /&gt;Error Message %ASA-1-105008: (Primary) Testing interface interface_name.&lt;BR /&gt;&lt;BR /&gt;Explanation Testing of a specified network interface has occurred. This testing is performed only if the ASA fails to receive a message from the standby unit on that interface after the expected interval. Primary can also be listed as Secondary for the secondary unit.&lt;BR /&gt;&lt;BR /&gt;Recommended Action None required.</description>
      <pubDate>Sun, 24 Feb 2019 19:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-active-standby-failover/m-p/3808650#M6788</guid>
      <dc:creator>cisc0.ameer</dc:creator>
      <dc:date>2019-02-24T19:23:59Z</dc:date>
    </item>
  </channel>
</rss>

