<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-failure/m-p/3930518#M937966</link>
    <description>&lt;P&gt;It appears you have a "split brain" situation where both ASA units believe they should be in the Active role.&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;HELLO not heard from mate&lt;/SPAN&gt;" means the mate is offline or the failover link is not communicating the HELLO keepalive messages.&lt;/P&gt;
&lt;P&gt;The hostname should replicate between the units. In HA pairs we typically recommend modifying the prompt so that you can see the role and state immediately when you log in.&lt;/P&gt;
&lt;P&gt;Re the Firepower module are you saying you only have it on one of the two units? You can exclude it from monitoring for failover purposes but this is not a recommended configuration for most situations.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2019 02:14:02 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-09-26T02:14:02Z</dc:date>
    <item>
      <title>Failover failure</title>
      <link>https://community.cisco.com/t5/network-security/failover-failure/m-p/3930211#M937962</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a firewall configured active/standy lan failover. Over the weekend there was something that happened and now the standby is active. Below i posted the failover state, for security purposes i just left out the actual ips on some. I know that one reason the failover has failed is due to the firepower module which will only run properly when the primary is active. However, usually i can just make the primary active and the active/standby will go back to normal. I know this is not ideal, but i have zero experience with firepower and i didn't configure anything on these firewalls and limited experience in them as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So after this issue happened, this time, both firewalls are showing active based on the active lights on the device itself, which is different than before. usually the primary had the orange led for standby. While troubleshooting this, i found when i console into the secondary firewall, the command line still shows its' hostname as the primary firewall. Is this correct? Is that supposed to happen? Or does it take over the hostname as it does the mac/ip when failover happens?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question i have is why would the firepower module fail to load anytime the secondary is active? The logs for the failover history are below as well showing the failure. Possible firepower hardware issue on the secondary maybe?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Failover On&lt;BR /&gt;Failover unit Secondary&lt;BR /&gt;Failover LAN Interface: FO-1 GigabitEthernet1/8 (up)&lt;BR /&gt;Reconnect timeout 0:00:00&lt;BR /&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;BR /&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;BR /&gt;Interface Policy 1&lt;BR /&gt;Monitored Interfaces 1 of 160 maximum&lt;BR /&gt;MAC Address Move Notification Interval not set&lt;BR /&gt;Version: Ours 9.9(1), Mate 9.9(1)&lt;BR /&gt;Serial Number: Ours JAD20430ECN, Mate Unknown&lt;BR /&gt;Last Failover at: 12:48:15 EDT Sep 22 2019&lt;BR /&gt;This host: Secondary - Active&lt;BR /&gt;Active time: 248367 (sec)&lt;BR /&gt;slot 1: ASA5516 hw/sw rev (1.1/9.9(1)) status (Up Sys)&lt;BR /&gt;Interface outside (our pub ip): Normal (Not-Monitored)&lt;BR /&gt;Interface inside (192.168.1.4): Normal (Waiting)&lt;BR /&gt;Interface dmz (dmz ip): Normal (Not-Monitored)&lt;BR /&gt;Interface idf-link (idf ip): No Link (Not-Monitored)&lt;BR /&gt;slot 2: SFR5516 hw/sw rev (N/A/5.4.1-211) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.1-211, Up, (Monitored)&lt;BR /&gt;slot 2: SFR5516 hw/sw rev (N/A/5.4.1-211) status (Up/Up)&lt;BR /&gt;ASA FirePOWER, 5.4.1-211, Up, (Monitored)&lt;BR /&gt;Other host: Primary - Failed&lt;BR /&gt;Active time: 4391 (sec)&lt;BR /&gt;slot 1: ASA5516 hw/sw rev (1.1/9.9(1)) status (Unknown/Unknown)&lt;BR /&gt;Interface outside (0.0.0.0): Unknown (Not-Monitored)&lt;BR /&gt;Interface inside (192.168.1.5): Unknown (Monitored)&lt;BR /&gt;Interface dmz (dmz ip): Unknown (Not-Monitored)&lt;BR /&gt;Interface idf-link (idf ip): Unknown (Not-Monitored)&lt;BR /&gt;slot 2: SFR5516 hw/sw rev (N/A/5.4.1-211) status (Unknown/Unknown)&lt;BR /&gt;ASA FirePOWER, 5.4.1-211, Unknown, (Monitored)&lt;BR /&gt;slot 2: SFR5516 hw/sw rev (N/A/5.4.1-211) status (Unknown/Unknown)&lt;BR /&gt;ASA FirePOWER, 5.4.1-211, Unknown, (Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result of the command: "sh failover history"&lt;/P&gt;&lt;P&gt;==========================================================================&lt;BR /&gt;From State To State Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;11:37:57 EDT Sep 22 2019&lt;BR /&gt;Not Detected Negotiation No Error&lt;/P&gt;&lt;P&gt;11:38:01 EDT Sep 22 2019&lt;BR /&gt;Negotiation Cold Standby Detected an Active mate&lt;/P&gt;&lt;P&gt;11:38:02 EDT Sep 22 2019&lt;BR /&gt;Cold Standby Sync Config Detected an Active mate&lt;/P&gt;&lt;P&gt;11:38:21 EDT Sep 22 2019&lt;BR /&gt;Sync Config Sync File System Detected an Active mate&lt;/P&gt;&lt;P&gt;11:38:21 EDT Sep 22 2019&lt;BR /&gt;Sync File System Bulk Sync Detected an Active mate&lt;/P&gt;&lt;P&gt;11:38:37 EDT Sep 22 2019&lt;BR /&gt;Bulk Sync Standby Ready Detected an Active mate&lt;/P&gt;&lt;P&gt;11:38:37 EDT Sep 22 2019&lt;BR /&gt;Standby Ready Failed Detect service card failure&lt;/P&gt;&lt;P&gt;11:39:16 EDT Sep 22 2019&lt;BR /&gt;Failed Standby Ready My service card is as good as peer&lt;/P&gt;&lt;P&gt;11:39:36 EDT Sep 22 2019&lt;BR /&gt;Standby Ready Failed Detect service card failure&lt;/P&gt;&lt;P&gt;11:39:40 EDT Sep 22 2019&lt;BR /&gt;Failed Standby Ready My service card is as good as peer&lt;/P&gt;&lt;P&gt;12:48:15 EDT Sep 22 2019&lt;BR /&gt;Standby Ready Just Active HELLO not heard from mate&lt;/P&gt;&lt;P&gt;12:48:15 EDT Sep 22 2019&lt;BR /&gt;Just Active Active Drain HELLO not heard from mate&lt;/P&gt;&lt;P&gt;12:48:15 EDT Sep 22 2019&lt;BR /&gt;Active Drain Active Applying Config HELLO not heard from mate&lt;/P&gt;&lt;P&gt;12:48:15 EDT Sep 22 2019&lt;BR /&gt;Active Applying Config Active Config Applied HELLO not heard from mate&lt;/P&gt;&lt;P&gt;12:48:15 EDT Sep 22 2019&lt;BR /&gt;Active Config Applied Active HELLO not heard from mate&lt;/P&gt;&lt;P&gt;==========================================================================&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-failure/m-p/3930211#M937962</guid>
      <dc:creator>petoria</dc:creator>
      <dc:date>2020-02-21T17:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Failover failure</title>
      <link>https://community.cisco.com/t5/network-security/failover-failure/m-p/3930518#M937966</link>
      <description>&lt;P&gt;It appears you have a "split brain" situation where both ASA units believe they should be in the Active role.&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;HELLO not heard from mate&lt;/SPAN&gt;" means the mate is offline or the failover link is not communicating the HELLO keepalive messages.&lt;/P&gt;
&lt;P&gt;The hostname should replicate between the units. In HA pairs we typically recommend modifying the prompt so that you can see the role and state immediately when you log in.&lt;/P&gt;
&lt;P&gt;Re the Firepower module are you saying you only have it on one of the two units? You can exclude it from monitoring for failover purposes but this is not a recommended configuration for most situations.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 02:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-failure/m-p/3930518#M937966</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-26T02:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Failover failure</title>
      <link>https://community.cisco.com/t5/network-security/failover-failure/m-p/5197019#M1115980</link>
      <description>&lt;P&gt;Marvin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) How do you have the prompt/hostname display differently for the secondary in an HA situation?&lt;/P&gt;&lt;P&gt;2) If the Link and Stateful interfaces are directly connected to the ASAs at each end, why would the hello not be heard from the mate?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 18:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-failure/m-p/5197019#M1115980</guid>
      <dc:creator>Fishel Erps</dc:creator>
      <dc:date>2024-09-20T18:11:51Z</dc:date>
    </item>
  </channel>
</rss>

