<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover/sync issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370092#M975013</link>
    <description>&lt;P&gt;Thanks Marius,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes I believe the "failover lan unit secondary" was added, so unsure why we lost management access at the moment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if both PRIMARY &amp;amp; SECONDARY are active I take it when failover is turned on (#failover) then the boxes work it out between themselves using there lan unit status?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Apr 2018 19:14:00 GMT</pubDate>
    <dc:creator>marc07cisco</dc:creator>
    <dc:date>2018-04-20T19:14:00Z</dc:date>
    <item>
      <title>Failover/sync issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370078#M975011</link>
      <description>&lt;P&gt;Hi Cisco Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently replaced&amp;nbsp;our standby ASA5520, the failover was turned off on the primary box during the replacement being fitted(this is where we think our mistake has happened!!!).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once we had the upgraded the standby asa to&amp;nbsp;9.1(7.4)(same as primary). we turned the failover on the primary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We appear to have lost management access to the firewall, I think that the synchronised possibly from secondary&amp;nbsp;to primary because both boxes think they are the active box. Is there another possibility? Has the cluster&amp;nbsp; gone down because it need a box rebooting to decide which one is the active box?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are sending an engineer to site currently, I was going to get them to&amp;nbsp;console in(no remote console)&amp;nbsp;and reboot the secondary in hope that the configuration in the primary is still there.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370078#M975011</guid>
      <dc:creator>marc07cisco</dc:creator>
      <dc:date>2020-02-21T15:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failover/sync issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370085#M975012</link>
      <description>&lt;P&gt;If you configured the replacement secondary ASA with "failover lan unit secondary" it should not have overwritten the primary.&amp;nbsp; If this command was not added or it was configured to primary, you would have a split brain issue and it is possible that the active primary ASA configuration has been overwritten.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have done quite a few of these replacements and have never had to do a reboot of the ASA to get the failover up.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 19:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370085#M975012</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-20T19:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Failover/sync issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370092#M975013</link>
      <description>&lt;P&gt;Thanks Marius,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes I believe the "failover lan unit secondary" was added, so unsure why we lost management access at the moment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if both PRIMARY &amp;amp; SECONDARY are active I take it when failover is turned on (#failover) then the boxes work it out between themselves using there lan unit status?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 19:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370092#M975013</guid>
      <dc:creator>marc07cisco</dc:creator>
      <dc:date>2018-04-20T19:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Failover/sync issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370096#M975014</link>
      <description>&lt;P&gt;&lt;EM&gt;So if both PRIMARY &amp;amp; SECONDARY are active I take it when failover is turned on (#failover) then the boxes work it out between themselves using there lan unit status?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The ASA that is the current active primary will remain as the primary until a failover situation occurs or manually changed.&lt;/P&gt;
&lt;P&gt;You could issue the "show failover", "show failover history" and "show failover status" for more information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another possibility is that this is an ARP issue on the next hop device.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 19:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370096#M975014</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-20T19:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failover/sync issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370931#M975015</link>
      <description>Did you find out what actually happen?</description>
      <pubDate>Mon, 23 Apr 2018 08:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370931#M975015</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-04-23T08:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Failover/sync issue</title>
      <link>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370941#M975016</link>
      <description>Hi Florin,&lt;BR /&gt;&lt;BR /&gt;Not yet, we are hoping to get somone to site today to check. I will update the chat once we&lt;BR /&gt;Jave found out thanks&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Apr 2018 08:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-sync-issue/m-p/3370941#M975016</guid>
      <dc:creator>marc07cisco</dc:creator>
      <dc:date>2018-04-23T08:40:03Z</dc:date>
    </item>
  </channel>
</rss>

