09-19-2017 05:22 AM - edited 02-21-2020 06:19 AM
i have two 5512-x connected and configured with failover , we had firepower configured with one of them only "the secondary" , recently we found that failover under show failover is show primary - failed also under show failover history it shows "detect service card failure" , both are running 9.8 , is it because one of them only have firepower installed that the failover is failing? how do i know failure reason?
Solved! Go to Solution.
09-19-2017 05:46 AM
You may do this without a restart.
I'm assuming the primary firewall is in failed state and secondary is an active one.
1) Disable service module monitoring, save config (do it on the active firewall as usual);
2) Check if the primary firewall is standby ready;
3) If everything looks good, do #no failover active on the secondary/active firewall.
4) Primary should be the active one now, secondary should be standby ready and failover should be in a proper state.
09-19-2017 05:32 AM
You would be doing better by turning off the service module monitoring, so failover will not monitor the state of the FP module and will not failover.
#no monitor-interface service-module
Having FP running on one device of the failover pair is not a standard situation, does not make sense generally and may be considered as a failure by ASA - "service card failure" makes me think that's exactly the reason.
More information: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200944-Disable-Service-Module-Monitoring-on-ASA.html
09-19-2017 05:40 AM
09-19-2017 05:46 AM
You may do this without a restart.
I'm assuming the primary firewall is in failed state and secondary is an active one.
1) Disable service module monitoring, save config (do it on the active firewall as usual);
2) Check if the primary firewall is standby ready;
3) If everything looks good, do #no failover active on the secondary/active firewall.
4) Primary should be the active one now, secondary should be standby ready and failover should be in a proper state.
09-19-2017 11:25 PM
thank you so much for the help , the command worked but i still needed to restart the primary to get the standby status though
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide