<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Active/Standby Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966013#M939992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I can ping from primary to secondary fine.&lt;/P&gt;&lt;P&gt;I also configured standby addresses everywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the config from the active..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;failover polltime unit msec 200 holdtime msec 800&lt;/P&gt;&lt;P&gt;failover polltime interface msec 500 holdtime 5&lt;/P&gt;&lt;P&gt;failover link stateful GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.20.9 255.255.255.252 standby 192.168.20.1&lt;/P&gt;&lt;P&gt;0&lt;/P&gt;&lt;P&gt;failover interface ip stateful 192.168.20.13 255.255.255.252 standby 192.168.20.&lt;/P&gt;&lt;P&gt;14&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Apr 2008 15:26:48 GMT</pubDate>
    <dc:creator>amohabir1</dc:creator>
    <dc:date>2008-04-01T15:26:48Z</dc:date>
    <item>
      <title>ASA Active/Standby Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966011#M939990</link>
      <description>&lt;P&gt;I have two ASA 5520's setup in an active standby configuration. Each pix is configured with a inside and outside interface. I am also using the other two interfaces for the failover, and stateful pair. These firewall's are directly plugged into each other (no switches in between, I don't have any cross over cables so right now they are connected using straight through cables)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sourcing a ping from my laptop to a website, and then I force a fail on the active firewall by unplugging one of the monitored interfaces. The failover works but it seems to take too long to failover. I timed it and found that I am able to recover my ping close to a minute later after the failover has happened. Is this normal behavior or is there something wrong in my setup. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966011#M939990</guid>
      <dc:creator>amohabir1</dc:creator>
      <dc:date>2019-03-11T12:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966012#M939991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's definitely not normal, even with default timeouts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the same interface for failover and stateful failover, btw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you ping the failover (standby) IP addresses from the active ASA?  I mean, the IP address that is directly connected with the straight through cable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post your failover config?&lt;/P&gt;&lt;P&gt;"sh run failover"&lt;/P&gt;&lt;P&gt;also, did you configure standby addresses on your interfaces?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 14:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966012#M939991</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-04-01T14:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966013#M939992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I can ping from primary to secondary fine.&lt;/P&gt;&lt;P&gt;I also configured standby addresses everywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the config from the active..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;failover polltime unit msec 200 holdtime msec 800&lt;/P&gt;&lt;P&gt;failover polltime interface msec 500 holdtime 5&lt;/P&gt;&lt;P&gt;failover link stateful GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.20.9 255.255.255.252 standby 192.168.20.1&lt;/P&gt;&lt;P&gt;0&lt;/P&gt;&lt;P&gt;failover interface ip stateful 192.168.20.13 255.255.255.252 standby 192.168.20.&lt;/P&gt;&lt;P&gt;14&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 15:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966013#M939992</guid>
      <dc:creator>amohabir1</dc:creator>
      <dc:date>2008-04-01T15:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Active/Standby Failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966014#M939993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay so I figured out what was causing the issue. I have an ospf procces running. The setup included 2 layers of asa firewalls. The first set of firewalls connects to the internet on the outside interface and an internet dmz on the inside interface running failover. I generate a default route of 0.0.0.0 0.0.0.0 and advertise that to the second  set of firewalls...these firewalls sit on the same dmz segment as the internet firewalls as well as protect the real inside network. The default route is then propogated to the core and beyond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the firewall failover happens the ospf process has to start up again on the firewall which essentially shuts it down and causes the default route to be advertised once its learned again. It uses the default ospf timers to send the hello's to establish the adjacency. Once it is re-learned by the ASA traffic starts to flow again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is what is the best way to handle this situation. should I just statically assign default routes on the 2 layers of firewalls as well as default routes for all of the routers participating in the inside network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 02:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-failover/m-p/966014#M939993</guid>
      <dc:creator>amohabir1</dc:creator>
      <dc:date>2008-04-02T02:29:48Z</dc:date>
    </item>
  </channel>
</rss>

