02-17-2016 11:23 AM - edited 03-12-2019 12:19 AM
Hello All,
I have a very strange issue with redundancy between two 5545X's. Failover is working fine but the only thing is that the "http" commands do not synch from the active to the standby. These are the commands for ASDM access, such as "http 0.0.0.0 0.0.0.0 outside". When I enter this command on the Primary and then do a "failover exec standby show run" I do not see it in the show run. I can enter other commands such as "ssh 0.0.0.0 0.0.0.0 management", which will show up on the standby. I have tried rebuilding the standby by defaulting its config then readding it as a standby device, the config all synchs except for those http commands. The reason why I discovered this is because a users couldnt not login to ASDM after we failed over. Also If I do failover, and then add the command and it will stick on the standby. Also if I do a "write standby", it will delete the "http" commands from the standby. It like the active just doesnt want to sync those "http" commands, has anyone seen this behavior before? I did open a TAC case. Thanks
Jason
02-17-2016 02:20 PM
9.5(2) is bleeding new. It will be a software bug.
HOWEVER, let me be the first discourage allowing remote management access from anywhere on the Internet. Please at least limit it to known IP addresses.
02-25-2016 06:20 AM
Philip,
Thanks, yes I have been doing this for testing pourposes. We will limit it. I have a TAC case open and they are looking into it. I also assume it a bug. Thanks
Jason
02-25-2016 07:27 AM
It looks like you are hitting following defect.
https://tools.cisco.com/bugsearch/bug/CSCuy45475/?reffering_site=dumpcr
You need to enable standby IP address on interface as a workaround.
Thanks,
Ishan
Please remember to select a correct answer and rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide