<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reg. failover query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481579#M745720</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Magnus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply . However over here my prime focus is still the difference between using cross cable and switch for the failover , hence my previous question . I want to confirm that while using switch (if any of the failover interface fails ) , then the next step is obviously the interface checks so that the healthy firewall can determine whether its peer is reachable or not . But if we use cross over cable , the step of interface checking never happens as failover links are the one who send heartbeats and if both of them will show as failed ( scenario 1 - cross over cable&amp;nbsp; ) , the process of failover will never initiate and we need to work upon rectifying the issue and making both the interfaces functional .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically with the above query in my mind , i am trying to make myself convince as to what i am thinking is right , Please share your thoughts .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i believe with the scenario 1 ( cross over cable ) , when both failover links fail ; there will be no disruption of the network traffic flow . right ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Aug 2010 10:41:49 GMT</pubDate>
    <dc:creator>ankurs2008</dc:creator>
    <dc:date>2010-08-04T10:41:49Z</dc:date>
    <item>
      <title>Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481573#M745714</link>
      <description>&lt;P&gt;Hi halijenn / experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a query related to failover and want to know as to what exactly is the advantage of using the switch between the 2 devices . If i am using cross over cable for the failover interfaces , i can understand that if cable is bad or any of the asa failover interface ports is faulty , it may lead to communication failure . Hence what is the advantage of using a switch in place of cross over cables&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481573#M745714</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2019-03-11T18:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481574#M745715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This comes from the failover configuration guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html&lt;/A&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;When you use a crossover cable for the LAN 
failover link, if the LAN interface fails, the link is brought down on 
both peers. This condition may hamper troubleshooting efforts because 
you cannot easily determine which interface failed and caused the link 
to come down.
&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2010 12:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481574#M745715</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-08-03T12:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481575#M745716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already gone through the document .I want to know if connectivity between the failover links is via switch and if any 1 of the switch port (to which the other end of the ASA failover interface cable is connected) goes down , will the link on the other ASA be up or will it show down ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;&lt;STRONG&gt;ASA1 (F/O Interface - Gig 0/3) ====&lt;SPAN style="color: #0000ff;"&gt;Fa0/2 --(Switch) --Fa0/3&lt;/SPAN&gt;======(F/O Interface - Gig 0/3) ASA2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;&lt;SPAN style="color: #000000;"&gt;Consider &lt;STRONG&gt;ASA 1 is acting as Primary&lt;/STRONG&gt; (currently Active ) and &lt;STRONG&gt;ASA 2 is Secondary&lt;/STRONG&gt; (Currently Standby)&lt;/SPAN&gt; .&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;If the corresponding switchport of the ASA 1 Firewall i.e Fa0/2 goes faulty then whether the link on the ASA 2 will keep on showing up or down ? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;&lt;SPAN style="color: #333333;"&gt;In addition to that what are the other advantages of the keeping the switch ?&lt;/SPAN&gt; &lt;SPAN style="color: #000000;"&gt;Also by keeping switch in between is there any delay in the configuration replication from Active to Standby ?&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2010 21:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481575#M745716</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-03T21:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481576#M745717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ankurs,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; With a switch in the middle, a failure of one interface will not affect the peer's interface (will still stay up). It is advised to use a switch for this reason.&amp;nbsp;&amp;nbsp; In your example, a failure of Fa0/2 will not impact Fa0/3 by design. A switch will have zero impact on config replication performance or any replication of connections etc.&amp;nbsp;&amp;nbsp;&amp;nbsp; - Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2010 21:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481576#M745717</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-08-03T21:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481577#M745718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Magnus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a ton ! i want to ask one more thing in context to this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) With cross over cable between 2 failover links&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If any one of the ASA failover interface is down , the failover link is brought down . Hence due to this there will be no failover as the failover link is the one thru which heartbeats are send across .Hence both the firewalls will remain in the state in which they are in , currently .Please correct me if i am wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) With switch between 2 failover links&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If any of the ASA failover interface is down , the firewall with the healthy failover interface will start the interface tests .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if my understanding is correct&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 02:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481577#M745718</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-04T02:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481578#M745719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ankurs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The key to understanding failover is that we only change from STANDBY to ACTIVE if we determine we are 'healthier' that the peer. Device health is comprised of interface statuses (up and functional) and device health (firewall up/down) and also module health (If you have an IPS or CSC module).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a great document online that shows the different failover scenarios:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#actio"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#actio&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the relevant chunk:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE bgcolor="#ffffff" border="1" cellpadding="3" cellspacing="1" style="width: 60%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;TD bgcolor="FFFFFF"&gt;&lt;P&gt;Failover link failed within operation&lt;/P&gt;&lt;/TD&gt;&lt;TD bgcolor="FFFFFF"&gt;&lt;P&gt;No failover&lt;/P&gt;&lt;/TD&gt;&lt;TD bgcolor="FFFFFF"&gt;&lt;P&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD bgcolor="FFFFFF"&gt;&lt;P&gt;Mark failover interface as failed&lt;/P&gt;&lt;/TD&gt;&lt;TD bgcolor="FFFFFF"&gt;&lt;P&gt;You must restore the failover link as soon as possible because&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;the unit cannot failover to the standby unit while the failover link is&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;down.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 03:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481578#M745719</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-08-04T03:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481579#M745720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Magnus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply . However over here my prime focus is still the difference between using cross cable and switch for the failover , hence my previous question . I want to confirm that while using switch (if any of the failover interface fails ) , then the next step is obviously the interface checks so that the healthy firewall can determine whether its peer is reachable or not . But if we use cross over cable , the step of interface checking never happens as failover links are the one who send heartbeats and if both of them will show as failed ( scenario 1 - cross over cable&amp;nbsp; ) , the process of failover will never initiate and we need to work upon rectifying the issue and making both the interfaces functional .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically with the above query in my mind , i am trying to make myself convince as to what i am thinking is right , Please share your thoughts .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i believe with the scenario 1 ( cross over cable ) , when both failover links fail ; there will be no disruption of the network traffic flow . right ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 10:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481579#M745720</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-04T10:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481580#M745721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Magnus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if my understanding is right . thanks !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 08:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481580#M745721</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-06T08:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481581#M745722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me on my query&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Aug 2010 12:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481581#M745722</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-08T12:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481582#M745723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ankur,&lt;/P&gt;&lt;P&gt;Your understanding is partially correct.&lt;/P&gt;&lt;P&gt;1. cross over cable - as you understood is not a good idea. Connection via a switch is the way to go.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. when failover cable breaks&amp;nbsp; and along with that primary/act untit loses interfaces - secondary unit should take over if it has more interfaces up than the primary/act. This is resolved with thi: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsw37519"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsw37519&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCsw37519&amp;nbsp;&amp;nbsp;&amp;nbsp; ENH Failover ability to switchover if FO LAN communication is severed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-family: monospace; font-size: 12px; white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;BR /&gt;This is an ENHANCEMENT request only.&lt;BR /&gt;&lt;BR /&gt;This enhancement request is to modify the behavior of failover, such that &lt;BR /&gt;if the LAN interface communication is severed, then the ASAs will attempt &lt;BR /&gt;to detect if only the LAN interface has an issue, or if other interfaces are &lt;BR /&gt;detected, and then make it's failover decision at that point.&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;BR /&gt;Active/Standby Failover, where the LAN communication is severed, causing &lt;BR /&gt;the Active unit to remain Active, but additional interfaces on the Active unit&lt;BR /&gt;also failed, causing traffic to be black-holed, as no switchover took place.&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;BR /&gt;Configure Redundant interfaces for the LAN Failover interface - &lt;BR /&gt;taking different paths to reach the two ASAs.&lt;BR /&gt;&lt;BR /&gt;-KS&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Aug 2010 13:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481582#M745723</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-08T13:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481583#M745724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi kusankar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply ; however i am not sure as to if this is the answer i am looking for , though it is definitely informative .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) With the below scenario , when one Failover LAN Interface fails (say Gig0/3 of the ASA1 which is Prim/Act) , both failover links will show down&amp;nbsp; .In this case whether there will be disruption of the network traffic flow or not ? (as we know that according to cisco doc both will continue to remain designated to their current positions and no failover will happen )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;&lt;STRONG&gt;ASA1 (F/O Interface - Gig 0/3) ====&lt;SPAN style="color: #0000ff;"&gt;CROSS CABLE&lt;/SPAN&gt;======(F/O Interface - Gig 0/3) ASA2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If the LAN Failover Interface communication among 2 ASA 's fail (and data interfaces of these ASA are fine and up ) , there is no switchover&amp;nbsp; Does the enhancement for the below bug is trying to tell that inspite of the LAN failover interface being down on any one of the ASA&amp;nbsp; (and then failover links Gig 0/3 brought down for both ASA) ,&amp;nbsp; failover should take place ?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 10:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481583#M745724</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-10T10:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481584#M745725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi kusankar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need your expert comments on the same&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 10:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481584#M745725</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-11T10:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481585#M745726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ankur,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) With the below scenario , when one Failover LAN Interface fails (say Gig0/3 of the ASA1 which is Prim/Act) , both failover links will show down&amp;nbsp; .In this case whether there will be disruption of the network traffic flow or not ? (as we know that according to cisco doc both will continue to remain designated to their current positions and no failover will happen )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;&lt;STRONG&gt;ASA1 (F/O Interface - Gig 0/3) ====&lt;SPAN style="color: #0000ff;"&gt;CROSS CABLE&lt;/SPAN&gt;======(F/O Interface - Gig 0/3) ASA2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct. Unless the primary active unit loses more interfaces than the sec/standby in which case there will be a failover as the standby unit will be deemed healthier than the active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You understood the ENH defect correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 11:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481585#M745726</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-11T11:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481586#M745727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks a ton !!! in the case 1 , whether there will be disruption of the network traffic flow or not ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 13:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481586#M745727</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-11T13:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481587#M745728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope. Shouldn't be any disruption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 13:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481587#M745728</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-11T13:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Reg. failover query</title>
      <link>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481588#M745729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks a ton again and excellent explantion !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 14:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-failover-query/m-p/1481588#M745729</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-08-11T14:18:54Z</dc:date>
    </item>
  </channel>
</rss>

