active failover config, dmz is showing normal waiting contineously
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-12-2011 02:21 PM - edited 03-11-2019 12:50 PM
hi,
I am configuring cisco asa5510
inside, outside saying normal normal, but dmz is showing normal waiting.
how to resolve this issue?
- Labels:
-
NGFW Firewalls

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-12-2011 02:46 PM
a couple of questions
1. do you have a primary and secondary IP on the DMZ interface?
2. If so, can you ping from one DMZ IP to the other DMZ IP?
They need to have IP connectivity in order to show normal normal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-13-2011 02:12 AM
if there is at least one switch between the two firewalls, ensure that the dmz VLAN is
passing between the two devices. Debug failover with interface related options will help you narrow the issue down. What does the other ASA say for failover status?
If you do not enter a failover IP address, the show failover command displays 0.0.0.0 for the IP address and interface monitoring remains in a waiting state.
