cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


168
Views
0
Helpful
0
Replies
Highlighted
Beginner

Traffic stopped passing through after failover to secondary ASA 5580

We are currently working on an issue where, as the title suggests, after failover of active FW from primary to secondary, there was no traffic passing through the secondary(active) FW. Due to this, the active FW was immediately failedback to primary. After a while, the field engineer performed, "write standby" on the primary FW.

However, another failover attempt couldn't performed to troubleshoot as the network is very critical in nature.

While trying to find the root cause of this issue, we made the following observations,

  1. Its ASA 5580 with version, 9.1(7.15), which has this bug,  CSCvd78303, due to which the ASA may stop passing traffic after 213 days of uptime. However, it was confirmed that the asa was anyhow restarted, hence, this may not be the issue.
  2. After looking in more detail about "write standby"command, I realised, it should normally be avoided and if needed, only upon advise of Cisco TAC.
  3. After doing "show failover history", the time duration between the moment when failover was done on primary to secondary and when secondary actually became active was approx. 20mins. Not sure, if this is normal.
  4. "show failover history" also showed, "configuration mismatch between the primary and secondary.
  5. Another major point was, there were no .cfg files present on the secondary ASA.

We had no ASA logs after the outage to determine, what exactly happened to the traffic, there is a non-cisco IPS behind the ASAs, but it was also confirmed no traffic passed through the secondary asa. 

 

TAC also has been engaged to look into this case, but we have had no concrete response as to why this must have happened and how it can be resolved.

 

I strongly feel, pts 4 & 5 could be a major cause here, as it would be quite obvious that secondary becomes active and it finds no config files in its flash, how would it even operate? But, as I am not an ASA expert, I can't be sure. 

 

We are also thinking to manually copy the .cfg files from primary to secondary and attempt another failover to see if it works.

 

Hence, can someone please advise what could be the probable cause of this issue and how it can be resolved ?