<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA, tracking, failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482537#M689134</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a problem when I put in the tracking option on my default route, I lose connection all together.&lt;/P&gt;&lt;P&gt;I have a T1 (outside) used as primary connection, and a DSL line (backup) plugged in for a failover.&lt;/P&gt;&lt;P&gt;This is an ASA with the Security Plus package, so the failover option should be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.2.3.1 1&lt;/P&gt;&lt;P&gt;route backup 0.0.0.0 0.0.0.0 7.8.9.1 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are my routes.&amp;nbsp; When I try to put:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.2.3.1 1 track 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I completely lose connection.&amp;nbsp; I've even tried "write mem" and "reload" hoping to bring up the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config that pertains to the routes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.253 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 1.2.3.2 255.255.255.248&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif backup&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 7.8.9.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.2.3.1 1&lt;/P&gt;&lt;P&gt;route backup 0.0.0.0 0.0.0.0 7.8.9.1 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor 666&lt;/P&gt;&lt;P&gt; type echo protocol ipIcmpEcho 1.2.3.4 interface outside&lt;/P&gt;&lt;P&gt; num-packets 3&lt;/P&gt;&lt;P&gt; frequency 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 1 rtr 666 reachability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't put in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor schedule 666 life forever start-time now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet because I want to make sure the default route works.&amp;nbsp; My understanding is that just adding in "track 1" to the end of the route doesn't do anything until I activate the timer with the "sla monitor" line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to which part of this feature I have wrong?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:52:11 GMT</pubDate>
    <dc:creator>scott.bridges</dc:creator>
    <dc:date>2019-03-11T17:52:11Z</dc:date>
    <item>
      <title>ASA, tracking, failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482537#M689134</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a problem when I put in the tracking option on my default route, I lose connection all together.&lt;/P&gt;&lt;P&gt;I have a T1 (outside) used as primary connection, and a DSL line (backup) plugged in for a failover.&lt;/P&gt;&lt;P&gt;This is an ASA with the Security Plus package, so the failover option should be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.2.3.1 1&lt;/P&gt;&lt;P&gt;route backup 0.0.0.0 0.0.0.0 7.8.9.1 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are my routes.&amp;nbsp; When I try to put:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.2.3.1 1 track 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I completely lose connection.&amp;nbsp; I've even tried "write mem" and "reload" hoping to bring up the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config that pertains to the routes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.253 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 1.2.3.2 255.255.255.248&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif backup&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 7.8.9.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.2.3.1 1&lt;/P&gt;&lt;P&gt;route backup 0.0.0.0 0.0.0.0 7.8.9.1 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor 666&lt;/P&gt;&lt;P&gt; type echo protocol ipIcmpEcho 1.2.3.4 interface outside&lt;/P&gt;&lt;P&gt; num-packets 3&lt;/P&gt;&lt;P&gt; frequency 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 1 rtr 666 reachability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't put in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor schedule 666 life forever start-time now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet because I want to make sure the default route works.&amp;nbsp; My understanding is that just adding in "track 1" to the end of the route doesn't do anything until I activate the timer with the "sla monitor" line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to which part of this feature I have wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482537#M689134</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2019-03-11T17:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, tracking, failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482538#M689155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you verified if the track statement is up with "sh sla monitor operational-state"? Have you configured the global statement for the backup link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Becasue if for whatever reason the track fails then the backup should take over as in your case. So verify those two things.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 17:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482538#M689155</guid>
      <dc:creator>Kelvin Willacey</dc:creator>
      <dc:date>2010-05-28T17:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, tracking, failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482539#M689192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I would suggest following &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml#cli"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml#cli&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The config will look like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 &lt;GW1 ip=""&gt; 1 track 1&lt;BR /&gt;route backup 0.0.0.0 0.0.0.0 &lt;GW2 ip=""&gt; 254&lt;/GW2&gt;&lt;/GW1&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor 123&lt;BR /&gt; type echo protocol ipIcmpEcho &lt;IP to="" monitor=""&gt; interface outside&lt;BR /&gt; num-packets 3&lt;BR /&gt; frequency 10&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor schedule 123 life forever start-time now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;track 1 rtr 123 reachability&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 May 2010 00:42:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482539#M689192</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-05-29T00:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, tracking, failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482540#M689240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys and sorry for the delay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't know about the show operational state command, which lead me to see that the ICMP was timing out.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I then just started from scratch, changed the instance to the example "123" exactly how it was in the post, and changed the test IP to the T1 lines' DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All worked after that point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&amp;nbsp; I was thinking I could change the "123", which I probably can, but I'll just keep it at default.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 05:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover/m-p/1482540#M689240</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2010-06-11T05:28:13Z</dc:date>
    </item>
  </channel>
</rss>

