<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5540 - Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378843#M731834</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I checked the ASA 5540 specs and the firewall throughput is 650Mbps and the firewall and IPS thoughput is 500Mbps with AIP-SSM20.&lt;/P&gt;&lt;P&gt;So I am not clear which thoughput is applied to firewall:&lt;/P&gt;&lt;P&gt;1. Without AIP-SSM card firewall thoughput is 650M?&lt;/P&gt;&lt;P&gt;2. With AIP-SSM card firewall thoughput is 500M?&lt;/P&gt;&lt;P&gt;If item 2 is true then my firewall thoughput is 500M instead of 650M?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration for the SSM to ASA is inline mode.&amp;nbsp; Trace back to the history and approximately 10 to 15 minutes before the failover&lt;/P&gt;&lt;P&gt;took place, the Unix admin experience slowness on his servers to internet users accessing the webpage/webcontain.&amp;nbsp; When the failover&lt;/P&gt;&lt;P&gt;happened approximately 2 minutes after everything is back to normal.&amp;nbsp; Web traffice before the failover is around 350Mbps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jan 2010 14:16:19 GMT</pubDate>
    <dc:creator>ttran</dc:creator>
    <dc:date>2010-01-19T14:16:19Z</dc:date>
    <item>
      <title>ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378837#M731828</link>
      <description>&lt;P&gt;Last night my firewall failover to secondary suddenly and I am still trying to find the root cause.&amp;nbsp; Looking at the log and history, I saw the reason of failover because the "Service card in other unit has failed".&amp;nbsp; Further investigating and the card is SSM according to Cisco web page.&amp;nbsp; So I think it is the AIP-SSM card.&amp;nbsp; Still do not know why the card was failed that trigger the failover.&amp;nbsp; ASA running code 8.0.4.&amp;nbsp; Right now the secondary is still the active ASA.&amp;nbsp; We have the Netscaler in the DMZ doing web hosting.&amp;nbsp; Could it be to much traffic for the ASA and/or AIP-SSM to handle? Anyone has any idea is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378837#M731828</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2019-03-11T16:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378838#M731829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There could be multiple reasons a card could fail.&lt;/P&gt;&lt;P&gt;Software defect, hardware issue in the backplane, just a glitch, overload of the card, these are some.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to investigate if the card keeps failing or if it was an one off event.&lt;/P&gt;&lt;P&gt;to reset the card do "hw module 1 reset" on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jan 2010 22:47:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378838#M731829</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-01-15T22:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378839#M731830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What output does you get from the module when you do the `show module` command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Jan 2010 10:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378839#M731830</guid>
      <dc:creator>Kent Heide</dc:creator>
      <dc:date>2010-01-16T10:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378840#M731831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to swap the AIP SSM module in the ASA with a spare KNOWN GOOD module and monitor the performance of card.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jan 2010 01:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378840#M731831</guid>
      <dc:creator>vilaxmi</dc:creator>
      <dc:date>2010-01-18T01:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378841#M731832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to try swapping the AIP SSM module on your ASA with a KNOWN GOOD CARD, and then monitor the performance, as this could be a hardware fault.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jan 2010 01:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378841#M731832</guid>
      <dc:creator>vilaxmi</dc:creator>
      <dc:date>2010-01-18T01:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378842#M731833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you everyone answer this question.&amp;nbsp; The AIP-SSM20 card is still functioning after the failover.&lt;/P&gt;&lt;P&gt;I was able to ssh to the card and show version to make sure the apps and engine is running.&lt;/P&gt;&lt;P&gt;Show module indicated the card is up state.&amp;nbsp; This is still in mystery.&lt;/P&gt;&lt;P&gt;This was the first time it happened so not sure what cause it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jan 2010 17:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378842#M731833</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2010-01-18T17:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378843#M731834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I checked the ASA 5540 specs and the firewall throughput is 650Mbps and the firewall and IPS thoughput is 500Mbps with AIP-SSM20.&lt;/P&gt;&lt;P&gt;So I am not clear which thoughput is applied to firewall:&lt;/P&gt;&lt;P&gt;1. Without AIP-SSM card firewall thoughput is 650M?&lt;/P&gt;&lt;P&gt;2. With AIP-SSM card firewall thoughput is 500M?&lt;/P&gt;&lt;P&gt;If item 2 is true then my firewall thoughput is 500M instead of 650M?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration for the SSM to ASA is inline mode.&amp;nbsp; Trace back to the history and approximately 10 to 15 minutes before the failover&lt;/P&gt;&lt;P&gt;took place, the Unix admin experience slowness on his servers to internet users accessing the webpage/webcontain.&amp;nbsp; When the failover&lt;/P&gt;&lt;P&gt;happened approximately 2 minutes after everything is back to normal.&amp;nbsp; Web traffice before the failover is around 350Mbps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2010 14:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378843#M731834</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2010-01-19T14:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378844#M731835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Throughput depends upon how traffic redirected to AIP module(using class map ), if all then there will be a bottleneck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about the IPS alerts, it will definitely give some answer that caused the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2010 05:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378844#M731835</guid>
      <dc:creator>Dileep Sivadas Padmini</dc:creator>
      <dc:date>2010-01-20T05:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378845#M731836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dileep.&amp;nbsp; My thought is the same since SSM in line will cause some problem with thoughput.&lt;/P&gt;&lt;P&gt;I tried to check the logs on the IPS but did not see anything out of ordinary (I think) since I am not able to show&lt;/P&gt;&lt;P&gt;any actual events back on January 14 just in general of tcp traffic and there is no idication of the attack.&amp;nbsp; For sure&lt;/P&gt;&lt;P&gt;I was able to see the ASA CPU hits around 75% as normal between 40% to 45% when traffic around 350M.&amp;nbsp; When&lt;/P&gt;&lt;P&gt;failover happened, there were few spike around 530M and the Secondary is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am planning to remove the inspect http from the global policy inspection.&amp;nbsp; Any idea how the ASA behave when&lt;/P&gt;&lt;P&gt;the inspection http is removed.&amp;nbsp; Is it a good idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK,&lt;/P&gt;&lt;P&gt;Thank you for answer from the other question and I know you did mention will causing some problem if inspection http is removed, is it going to be a big problem because http will not be inspect by the IPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2010 15:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-failover/m-p/1378845#M731836</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2010-01-20T15:40:36Z</dc:date>
    </item>
  </channel>
</rss>

