<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Stateful Failover problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459868#M726941</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear halijenn!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After ASA HA switchover and reload both devices, the err counters stop counting &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; The software version and HA configuration are the same as before, however we successfully migrated all ASA interfaces to gigabit speed, so all ASA interfaces (of both devices) operating at 1000 / full duplex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is an interesting story &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/confused.gif"&gt;&lt;/SPAN&gt; after the first reboot, everything seemed to be OK...suddenly the ASA ASDM service crashed, the "show asdm session" command output stated that, we reached the permitted concurrent ASDM session limit. I had &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;one &lt;/STRONG&gt;&lt;/SPAN&gt;active connection from 172.16.129.221 IP address. Trying to&amp;nbsp; disconnect the "stucked" sessions, but no luck...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall# show asdm sessions &lt;BR /&gt;0 mbela_172.16.129.221&lt;BR /&gt;1 mbela_172.16.129.221&lt;BR /&gt;2 mbela_172.16.129.221&lt;BR /&gt;3 mbela_172.16.129.221&lt;BR /&gt;4 mbela_172.16.129.221&lt;/P&gt;&lt;P&gt;firewall#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 0&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 1&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 2&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 3&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 4&lt;/P&gt;&lt;P&gt;firewall# show asdm sessions&lt;BR /&gt;0 mbela_172.16.129.221&lt;BR /&gt;1 mbela_172.16.129.221&lt;BR /&gt;2 mbela_172.16.129.221&lt;BR /&gt;3 mbela_172.16.129.221&lt;BR /&gt;4 mbela_172.16.129.221&lt;/P&gt;&lt;P&gt;firewall#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suddenly, I lost the SSH connection and the device rebooted. Finally,this reboot solved the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is annoying, because we don't know what was the real cause of the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for Your help!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Belabacsi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 May 2010 14:16:04 GMT</pubDate>
    <dc:creator>Bela Mareczky</dc:creator>
    <dc:date>2010-05-13T14:16:04Z</dc:date>
    <item>
      <title>ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459860#M726933</link>
      <description>&lt;P&gt;Dear Forum Community!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have recently implemented ASA stateful failover between two ASA 5540 operating at two different location. Unfortunately, because of a temporary switch installation, the standby peer has one physical interface at &lt;STRONG&gt;speed 100&lt;/STRONG&gt;-duplex full, while the primary device has all interface at &lt;STRONG&gt;speed 1000&lt;/STRONG&gt;-duplex full.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the output of the "show failover" command executed in the standby device below: the receive error counters shows that something is wrong with stateful HA.&lt;/P&gt;&lt;P&gt;Could anyone help me to find out, if the asymmetric interface speed could cause this symptom?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and BR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Belabacsi&lt;/P&gt;&lt;P&gt;Budapest, Hungary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Stateful Failover Logical Update Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Link : ***** (up)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Stateful Obj&amp;nbsp;&amp;nbsp;&amp;nbsp; xmit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; xerr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rcv&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;rerr&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; General&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 555244&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 696813995&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;65685015&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sys cmd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 555244&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 555244&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RPC services&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP conn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 199265403&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;56098066&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP conn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 487869778&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;9492795&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ARP tbl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9121627&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;94154&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xlate_Timeout&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN IKE upd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 556&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN IPSEC upd&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1132&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN CTCP upd&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN SDI upd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN DHCP upd&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SIP Session&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logical Update Queue Information&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cur&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Max&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Recv Q:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 138&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 713534140&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xmit Q:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 555244&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459860#M726933</guid>
      <dc:creator>Bela Mareczky</dc:creator>
      <dc:date>2019-03-11T17:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459861#M726934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right. Interface speed for the stateful failover link needs to be the same on both firewalls. It also needs to be the highest speed on your ASA, so the ASA that has the stateful interface down to 100, you would need to fix the interface so it's 1000, the same as the other ASA stateful interface speed.&lt;/P&gt;&lt;P&gt;Otherwise, you will be seeing what you are currently seeing, ie: receive error (rerr). The standby ASA can't receive the failover state information fast enough through the stateful link, hence you saw the received error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 21:38:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459861#M726934</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-29T21:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459862#M726935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear halijenn!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for Your reply, I think it helps to resolve the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just double-checked the configuration: the outside interface of the primary ASA has a speed 100-duplex full state, because it is connected to a temporary device which is C2960 10/100 switch &lt;span class="lia-unicode-emoji" title=":face_with_open_mouth:"&gt;😮&lt;/span&gt; Every other ports connect to gigabit switchport and have speed 1000-duplex full state, including gigabit 0/3 which serve as state and failover VLAN trunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary ASA:&lt;/P&gt;&lt;P&gt;###########&lt;/P&gt;&lt;P&gt;Outside: &lt;STRONG style="color: #ff0000; "&gt;speed 100/duplex full&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Inside: speed 1000/duplex full&lt;/P&gt;&lt;P&gt;DMZ: speed 1000/duplex full&lt;/P&gt;&lt;P&gt;HA: speed 1000/duplex full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary ASA:&lt;/P&gt;&lt;P&gt;#############&lt;/P&gt;&lt;P&gt;Outside: speed 1000/duplex full&lt;BR /&gt;Inside: speed 1000/duplex full&amp;nbsp; &lt;BR /&gt;DMZ: speed 1000/duplex full&lt;BR /&gt;HA: speed 1000/duplex full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do You think, the speed 100 state of the outside interface could also cause the errors?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Belabacsi&lt;/P&gt;&lt;H1&gt;&lt;/H1&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Apr 2010 09:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459862#M726935</guid>
      <dc:creator>Bela Mareczky</dc:creator>
      <dc:date>2010-04-30T09:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459863#M726936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Speed 100 on the outside interface is OK. However, I am concern about all the rerr that you are getting on the stateful failover link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to double check if the rerr errors are increasing. Also what version of ASA are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Apr 2010 13:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459863#M726936</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-30T13:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459864#M726937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear halijenn !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for Your reply, unfortunately the err counters are increasing... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA version information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.2(1)&lt;BR /&gt;Device Manager Version 6.2(5)&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; ASA5540, 1024 MB RAM, CPU Pentium 4 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do You think, it can be a software bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Belabacsi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 May 2010 07:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459864#M726937</guid>
      <dc:creator>Bela Mareczky</dc:creator>
      <dc:date>2010-05-03T07:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459865#M726938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the "show interface" output for the stateful failover link/interface on both ASA firewall. You might also want to check the corresponding switch interfaces/ports. Possibly it could be faulty cable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't think it's software bug at this stage. It's more looking like an interface issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 May 2010 10:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459865#M726938</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-03T10:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459866#M726939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear halijenn!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the tips! Unfortunataly, the switch interfaces connecting to the ASA seem to be OK, I hava fount no CRC / errors counting.&lt;/P&gt;&lt;P&gt;We have a scheduled maintenance window on Saturday, when we plan to force-switchover the ASA HA and reboot the device...we expect some posotive results &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I 'll inform You about the err counter status.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and BR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Belabacsi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 09:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459866#M726939</guid>
      <dc:creator>Bela Mareczky</dc:creator>
      <dc:date>2010-05-06T09:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459867#M726940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the update. Let us know how it goes after the reload.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 11:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459867#M726940</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-06T11:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459868#M726941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear halijenn!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After ASA HA switchover and reload both devices, the err counters stop counting &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; The software version and HA configuration are the same as before, however we successfully migrated all ASA interfaces to gigabit speed, so all ASA interfaces (of both devices) operating at 1000 / full duplex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is an interesting story &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/confused.gif"&gt;&lt;/SPAN&gt; after the first reboot, everything seemed to be OK...suddenly the ASA ASDM service crashed, the "show asdm session" command output stated that, we reached the permitted concurrent ASDM session limit. I had &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;one &lt;/STRONG&gt;&lt;/SPAN&gt;active connection from 172.16.129.221 IP address. Trying to&amp;nbsp; disconnect the "stucked" sessions, but no luck...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall# show asdm sessions &lt;BR /&gt;0 mbela_172.16.129.221&lt;BR /&gt;1 mbela_172.16.129.221&lt;BR /&gt;2 mbela_172.16.129.221&lt;BR /&gt;3 mbela_172.16.129.221&lt;BR /&gt;4 mbela_172.16.129.221&lt;/P&gt;&lt;P&gt;firewall#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 0&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 1&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 2&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 3&lt;/P&gt;&lt;P&gt;firewall# asdm disconnect 4&lt;/P&gt;&lt;P&gt;firewall# show asdm sessions&lt;BR /&gt;0 mbela_172.16.129.221&lt;BR /&gt;1 mbela_172.16.129.221&lt;BR /&gt;2 mbela_172.16.129.221&lt;BR /&gt;3 mbela_172.16.129.221&lt;BR /&gt;4 mbela_172.16.129.221&lt;/P&gt;&lt;P&gt;firewall#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suddenly, I lost the SSH connection and the device rebooted. Finally,this reboot solved the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is annoying, because we don't know what was the real cause of the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for Your help!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Belabacsi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 May 2010 14:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459868#M726941</guid>
      <dc:creator>Bela Mareczky</dc:creator>
      <dc:date>2010-05-13T14:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459869#M726942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear that upgrade resolves the issue. Please kindly mark the question as answered. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 09:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459869#M726942</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-14T09:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stateful Failover problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459870#M726943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear halijenn!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for Your help!&lt;/P&gt;&lt;P&gt;We have not upgraded the ASA software, the HA configuration and software version are the same as before...only the 2nd reboot solves the error counter issue &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/confused.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, we don't know the cause of the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Belabacsi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 12:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stateful-failover-problem/m-p/1459870#M726943</guid>
      <dc:creator>Bela Mareczky</dc:creator>
      <dc:date>2010-05-18T12:54:54Z</dc:date>
    </item>
  </channel>
</rss>

