cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
235
Views
1
Helpful
2
Replies

Line protocol failure caused by ISP outage?

irbk
Level 1
Level 1

My ASA had a failover event.  Failover worked just like it should.  Digging into the root cause of the failover I find
<164>Aug 02 2023 03:08:15: %ASA-4-411002: Line protocol on Interface GigabitEthernet0/5, changed state to down
Gi0/5 is my connection to the internet, so when he lost internet connectivity, we failed over to the secondary.  I go to my DC hosting provider and say "why did my gi0/5 go down for about 10 min between about 3:08 and 3:18".  The response I get is they believe it was due to ISP outages.  I've no idea how/what my ASA is plugged in at the hosted DC.  The traffic goes out Gi0/5 and it's not my problem after that.  I didn't get any "link state down" just "line protocol down".  While an line protocol down could be the issue, my gut is telling me that the hosting provider has no clue why we lost connectivity for 10 min and the ISP outage just happens to be a convenient excuse.  Do you think this is a reasonable enough answer or just an excuse and I need to push the DC host for a better explanation?

****EDIT****
I don't know why I missed it yesterday but looking at the logs again today, I see there is the protocol failure AND a link failure.  So it wasn't just protocol down.  IMHO I still think the hosted datacenter can't come up with a reason or doesn't want to admit to the reason why I had a 10 minute link failure and the ISP maintenance is just a convenient excuse.  Anyway, disregard the question.  I can't seem to just delete the post otherwise I would.

2 Replies 2

kyaw
Level 1
Level 1

Failover link does not depend on the ISP outage because failover link is directly connected between two asa firewalls. At that time, you should check the device status (uptime), failover link status and failover history on both firewalls.

If the interface is a monitored interface, losing connectivity on that interface certainly would cause a failover.