<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM Failover - packet drops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-failover-packet-drops/m-p/881186#M957665</link>
    <description>&lt;P&gt;I have configured the FWSM for Active Active failover. 2 VLANS (VLAN 7 and VLAN8) have been created for failover and state information to be replicated to other unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue: Replication does not happen. Secondary switch drops VLAN packets (see output below)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh interface vlan 7&lt;/P&gt;&lt;P&gt;Interface Vlan7 "Failover", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: LAN Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 001b.53a3.b600, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.41, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Failover":&lt;/P&gt;&lt;P&gt;        111 packets input, 76 bytes&lt;/P&gt;&lt;P&gt;        1222 packets output, 147228 bytes&lt;/P&gt;&lt;P&gt;        0 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh interface vlan 8&lt;/P&gt;&lt;P&gt;Interface Vlan8 "Stateful", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: STATE Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 001b.53a3.b600, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.49, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Stateful":&lt;/P&gt;&lt;P&gt;        12 packets input, 0 bytes&lt;/P&gt;&lt;P&gt;        34 packets output, 3340 bytes&lt;/P&gt;&lt;P&gt;        0 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh inter vlan 7&lt;/P&gt;&lt;P&gt;Interface Vlan7 "Failover", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: LAN Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 0018.7475.43c0, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.42, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Failover":&lt;/P&gt;&lt;P&gt;        997 packets input, 152 bytes&lt;/P&gt;&lt;P&gt;        1400 packets output, 150888 bytes&lt;/P&gt;&lt;P&gt;        1410 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh inter vlan 8&lt;/P&gt;&lt;P&gt;Interface Vlan8 "Stateful", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: STATE Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 0018.7475.43c0, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.50, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Stateful":&lt;/P&gt;&lt;P&gt;        32 packets input, 136 bytes&lt;/P&gt;&lt;P&gt;        50 packets output, 5034 bytes&lt;/P&gt;&lt;P&gt;        1182 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All in all - There is no communication between the VLANs on both unit.Not sure what the issue is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vinod&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:43:31 GMT</pubDate>
    <dc:creator>vinod.rathi</dc:creator>
    <dc:date>2019-03-11T11:43:31Z</dc:date>
    <item>
      <title>FWSM Failover - packet drops</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-failover-packet-drops/m-p/881186#M957665</link>
      <description>&lt;P&gt;I have configured the FWSM for Active Active failover. 2 VLANS (VLAN 7 and VLAN8) have been created for failover and state information to be replicated to other unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue: Replication does not happen. Secondary switch drops VLAN packets (see output below)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Primary FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh interface vlan 7&lt;/P&gt;&lt;P&gt;Interface Vlan7 "Failover", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: LAN Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 001b.53a3.b600, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.41, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Failover":&lt;/P&gt;&lt;P&gt;        111 packets input, 76 bytes&lt;/P&gt;&lt;P&gt;        1222 packets output, 147228 bytes&lt;/P&gt;&lt;P&gt;        0 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh interface vlan 8&lt;/P&gt;&lt;P&gt;Interface Vlan8 "Stateful", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: STATE Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 001b.53a3.b600, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.49, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Stateful":&lt;/P&gt;&lt;P&gt;        12 packets input, 0 bytes&lt;/P&gt;&lt;P&gt;        34 packets output, 3340 bytes&lt;/P&gt;&lt;P&gt;        0 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh inter vlan 7&lt;/P&gt;&lt;P&gt;Interface Vlan7 "Failover", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: LAN Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 0018.7475.43c0, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.42, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Failover":&lt;/P&gt;&lt;P&gt;        997 packets input, 152 bytes&lt;/P&gt;&lt;P&gt;        1400 packets output, 150888 bytes&lt;/P&gt;&lt;P&gt;        1410 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh inter vlan 8&lt;/P&gt;&lt;P&gt;Interface Vlan8 "Stateful", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is EtherSVI&lt;/P&gt;&lt;P&gt;        Description: STATE Failover Interface&lt;/P&gt;&lt;P&gt;        MAC address 0018.7475.43c0, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.0.224.50, subnet mask 255.255.255.248&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Stateful":&lt;/P&gt;&lt;P&gt;        32 packets input, 136 bytes&lt;/P&gt;&lt;P&gt;        50 packets output, 5034 bytes&lt;/P&gt;&lt;P&gt;        1182 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All in all - There is no communication between the VLANs on both unit.Not sure what the issue is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vinod&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-failover-packet-drops/m-p/881186#M957665</guid>
      <dc:creator>vinod.rathi</dc:creator>
      <dc:date>2019-03-11T11:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Failover - packet drops</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-failover-packet-drops/m-p/881187#M957667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Failover (and that includes Stateful failover) is only supported on devices running the same exact version. A mechanism exists in failover to verify the peer's version, and if it differs from the current version, then failover is dis-allowed.&lt;/P&gt;&lt;P&gt; &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_qanda_item09186a00801e9e26.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_qanda_item09186a00801e9e26.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2008 18:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-failover-packet-drops/m-p/881187#M957667</guid>
      <dc:creator>ebreniz</dc:creator>
      <dc:date>2008-01-10T18:01:31Z</dc:date>
    </item>
  </channel>
</rss>

