<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover/m-p/1437418#M856642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's the same situation,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m getting logs on console " NO response from Mate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jun 2010 19:39:46 GMT</pubDate>
    <dc:creator>lambay2000</dc:creator>
    <dc:date>2010-06-03T19:39:46Z</dc:date>
    <item>
      <title>Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437412#M856618</link>
      <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Please find the attached output for show failover:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring failover on PIX with IOS 7.2.2&amp;nbsp; with Active Active license on simulator&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int e3&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover link failover Ethernet3&lt;BR /&gt;failover interface ip failover 192.168.2.6 255.255.255.0 standby 192.168.2.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this i booted the secondary firewwall and applied a write standby command on active unit but no output,In stateful failover we dont need to specify on the standby unit but still i executed the&amp;nbsp; below command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int e3&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover link failover Ethernet3&lt;BR /&gt;failover interface ip failover 192.168.2.6 255.255.255.0 standby 192.168.2.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the output i think the cable connection between the 2 firewall.It is simulator so there is no point for straight and cross but the interfaces are up and protocol is also up.????? Correct me if i m wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437412#M856618</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2019-03-11T17:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437413#M856622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your config, it doesn't see the secondary firewall. Can you ping the secondary inside interface from the primary? Is the inside address of your secondary 192.168.1.7?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 15:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437413#M856622</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2010-06-03T15:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437414#M856627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes the inside interface of secondary is 192.168.1.7. Iti is pingable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it i m missing anything in my configs, My above steps for stateful failover are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 16:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437414#M856627</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-06-03T16:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437415#M856631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the interface configurations from both firewalls and the failover information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 18:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437415#M856631</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2010-06-03T18:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437416#M856635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached are the configs for Secondary PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My topology is, L3 switch connecting 2 firewall inside interface.and a dedicated interface for failover on the firewall.and also DMZ interface connecting to router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my previous configs i have choosen ethernet 3 as a failover interface but now i have changed to ehternet 4.on both the PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 18:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437416#M856635</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-06-03T18:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437417#M856638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, I see the problem. You have a STATE interface configured, but not the LAN side. Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover lan interface LAN eth4&lt;BR /&gt;failover interface ip LAN 192.168.2.6 255.255.255.0 standby 192.168.2.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe you can use the same interface for LAN and STATE. Your state interface is used to roll over the xlate tables. You don't *need* a state interface, but all connections would need to be manually reconnected again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*EDIT*: You'll need to do this on both firewalls&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try that and let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 19:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437417#M856638</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2010-06-03T19:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437418#M856642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's the same situation,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m getting logs on console " NO response from Mate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 19:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437418#M856642</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-06-03T19:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437419#M856646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the LAN and State interfaces, can you ping each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the primary, try to ping the secondary:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 192.168.2.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the secondary, try to ping the primary:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 192.168.2.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to remove the STATE interface until you get the LAN side working too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 19:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437419#M856646</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2010-06-03T19:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437420#M856650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cleared failover configs by&amp;nbsp; the command "clear configure failover "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m able to ping 192.168.1.6 and 192.168.1.7 which are the inside interface IP address but i m not able to ping failover ip address 192.168.2.6.and 192.168.2.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The state interface configuration has been cleared from the interface configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 19:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437420#M856650</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-06-03T19:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437421#M856654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks fine. What simulator are you using? Can you do a "sh int ip brief" and post those results?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 20:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437421#M856654</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2010-06-03T20:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437422#M856655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m using GNS3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX-1(config)#&amp;nbsp;&amp;nbsp; sh int ip brief&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK? Method Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Prot&lt;BR /&gt;ocol&lt;BR /&gt;Ethernet0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.146.254.2&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#####################################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX2(config)# sh int ip brief&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK? Method Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Prot&lt;BR /&gt;ocol&lt;BR /&gt;Ethernet0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES manual up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 20:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437422#M856655</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-06-03T20:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437423#M856659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only thing that I can figure is that GNS is having a problem. Your configs are correct, but the problem is that the secondary thinks it's the primary because of the LAN address of 192.168.2.6. (It's the same as the real primary).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a real configuration from my ASAs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary:&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface LAN GigabitEthernet1/2&lt;BR /&gt;failover link STATE GigabitEthernet1/1&lt;BR /&gt;failover interface ip LAN 10.14.14.1 255.255.255.252 standby 10.14.14.2&lt;BR /&gt;failover interface ip STATE 10.15.15.1 255.255.255.252 standby 10.15.15.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh int ip brie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet1/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.15.15.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;GigabitEthernet1/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.14.14.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary:&lt;/P&gt;&lt;P&gt;failover&lt;BR /&gt;failover lan unit secondary&lt;BR /&gt;failover lan interface LAN GigabitEthernet1/2&lt;BR /&gt;failover link STATE GigabitEthernet1/1&lt;BR /&gt;failover interface ip LAN 10.14.14.1 255.255.255.252 standby 10.14.14.2&lt;BR /&gt;failover interface ip STATE 10.15.15.1 255.255.255.252 standby 10.15.15.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh int ip brie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet1/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.15.15.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;GigabitEthernet1/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.14.14.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the unit is in standby mode, then it will be using the standby address of .7, not the .6 that it is using. Otherwise, your configs look right. Oh, and just to double check, make sure that the interfaces aren't shut that are being used for failover. That happened to me one day in GNS where it showed it apply the configuration, but the interface was shut. (It doesn't show in your config, but just to check.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 20:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437423#M856659</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2010-06-03T20:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Failover</title>
      <link>https://community.cisco.com/t5/network-security/failover/m-p/1437424#M856661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my sh ip int brief output my protocols are up,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configs u advice me to do by removing state and apply to LAN , we have configured LAN based failover by changing command to LAN. I m pretty sure ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U have used 2 seperate interface for LAN and stateful failover can i use 1 interface for stateful and LAN.?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover lan interface LAN GigabitEthernet1/2&amp;nbsp; ------------------------&amp;gt;this is LAN based failover&amp;nbsp; ????&lt;BR /&gt;failover link STATE GigabitEthernet1/1 -----------------------------&amp;gt; this is stateful failover???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 20:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover/m-p/1437424#M856661</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-06-03T20:33:00Z</dc:date>
    </item>
  </channel>
</rss>

