<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 - Stateful feature failed on LAN based active/stand in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489059#M733575</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try with "failover lan enable" on primary and secondary.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;Massimiliano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 May 2010 07:52:39 GMT</pubDate>
    <dc:creator>massimiliano.serafino</dc:creator>
    <dc:date>2010-05-18T07:52:39Z</dc:date>
    <item>
      <title>ASA 5520 - Stateful feature failed on LAN based active/standby failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489058#M733561</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Tableau Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Dear all,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I encoured stateful issue in a ASA 5520 architecture displayed on the drawing attached.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;This is a LAN based active/standby failover link between a pair of &lt;STRONG&gt;ASA5520 (version 8(0)4)&lt;/STRONG&gt;. Stateful and failover use the same ethernet link (dedeicated VLAN).&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;To test this architecture, I have lanch a FTP tansfert between trust and untruct zone. During the trnasfer I shutdown the Unit Primary.&lt;/P&gt;&lt;P class="MsoNormal" style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;SPAN style="font-family: Wingdings;"&gt;&lt;SPAN&gt;è&lt;SPAN style="font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;!--[endif]--&gt;The failover seems to work properly&lt;/P&gt;&lt;P class="MsoNormal" style="margin-left: 18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;SPAN style="font-family: Wingdings;"&gt;&lt;SPAN&gt;è&lt;SPAN style="font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;!--[endif]--&gt;The stateful doesn’t work properly becaise my FTP transfert is closed (see attachment)&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Find below my configuration :&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;description LAN Interface&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;speed 1000&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;duplex full&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;nameif outside&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;security-level 0&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;ip address 10.192.154.126 255.255.255.248 standby 10.192.154.125&lt;/P&gt;&lt;P class="MsoNormal"&gt;!&lt;/P&gt;&lt;P class="MsoNormal"&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;description ToIP Server Interface&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;speed 1000&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;duplex full&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;nameif inside&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;security-level 100&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;ip address 10.192.154.30 255.255.255.224 standby 10.192.154.29&lt;/P&gt;&lt;P class="MsoNormal"&gt;!&lt;/P&gt;&lt;P class="MsoNormal"&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;shutdown&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;no nameif&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;no security-level&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;no ip address&lt;/P&gt;&lt;P class="MsoNormal"&gt;!&lt;/P&gt;&lt;P class="MsoNormal"&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;description LAN/STATE Failover Interface&lt;/P&gt;&lt;P class="MsoNormal"&gt;!&lt;/P&gt;&lt;P class="MsoNormal"&gt;interface Management0/0&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;shutdown&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;no nameif&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;no security-level&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;no ip address&lt;/P&gt;&lt;P class="MsoNormal"&gt;!&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;STRONG&gt;Unit Primary :&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover lan unit primary&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover lan interface ASA_Failover GigabitEthernet0/3&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover key *****&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover link ASA_Failover GigabitEthernet0/3&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover interface ip ASA_Failover 10.192.154.110 255.255.255.252 standby 10.192.154.109&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt; &lt;STRONG&gt;Unit Secondary&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover lan unit secondary&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover lan interface ASA_Failover GigabitEthernet0/3&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover key *****&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover link ASA_Failover GigabitEthernet0/3&lt;/P&gt;&lt;P class="MsoNormal"&gt;failover interface ip ASA_Failover 10.192.154.110 255.255.255.252 standby 10.192.154.109&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Find also in attachment the result displayed by « sh failover »&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Anyone have an ideao of what is wrong in my configuration. My goal is to have no impact oin the current TCP/UDP session when the primary unit failed.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks for your help&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Regards,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Hervé&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489058#M733561</guid>
      <dc:creator>h-etchepare</dc:creator>
      <dc:date>2019-03-11T17:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - Stateful feature failed on LAN based active/stand</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489059#M733575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try with "failover lan enable" on primary and secondary.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;Massimiliano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 07:52:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489059#M733575</guid>
      <dc:creator>massimiliano.serafino</dc:creator>
      <dc:date>2010-05-18T07:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - Stateful feature failed on LAN based active/stand</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489060#M733591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition You've to define an interface&lt;/P&gt;&lt;P&gt;"state"...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#statef"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#statef&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;Massimiliano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 09:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489060#M733591</guid>
      <dc:creator>massimiliano.serafino</dc:creator>
      <dc:date>2010-05-18T09:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - Stateful feature failed on LAN based active/stand</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489061#M733603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;The issue is solved.&lt;/P&gt;&lt;P&gt;It was only a problem with DOS ftp client.&lt;/P&gt;&lt;P&gt;With filezilla the stateful works properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 07:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-stateful-feature-failed-on-lan-based-active-standby/m-p/1489061#M733603</guid>
      <dc:creator>h-etchepare</dc:creator>
      <dc:date>2010-05-19T07:29:51Z</dc:date>
    </item>
  </channel>
</rss>

