06-06-2011 07:45 AM - edited 03-11-2019 01:42 PM
Hi there,
I have this firewall working as active/standby. Everything seemed to be ok, but we noticed that confirgurations are not being replicated by saving configuration either copy run start or write. The workaround here is write standby command. Below the configs and stats, plus the show version, which is the same in both equipments:
Header 1 |
---|
failover failover lan unit primary failover lan interface failover Management0/0 failover link failover Management0/0 failover interface ip failover 1.1.1.1 255.255.255.252 standby 1.1.1.2 failover failover lan unit secondary failover lan interface failover Management0/0 failover link failover Management0/0 failover interface ip failover 1.1.1.1 255.255.255.252 standby 1.1.1.2 Failover On Failover unit Primary Failover LAN Interface: failover Management0/0 (up) Unit Poll frequency 1 seconds, holdtime 15 seconds Interface Poll frequency 5 seconds, holdtime 25 seconds Interface Policy 1 Monitored Interfaces 3 of 160 maximum Version: Ours 8.4(1), Mate 8.4(1) Last Failover at: 12:50:47 BRST May 21 2011 This host: Primary - Active Active time: 4498133 (sec) slot 0: ASA5520 hw/sw rev (2.0/8.4(1)) status (Up Sys) Interface inside (172.17.31.2): Normal (Monitored) Interface outside1 (200.169.226.168): Normal (Monitored) Interface outside2 (189.43.119.28): Normal (Monitored) slot 1: empty Other host: Secondary - Standby Ready Active time: 2221 (sec) slot 0: ASA5520 hw/sw rev (2.0/8.4(1)) status (Up Sys) Interface inside (172.17.31.3): Normal (Monitored) Interface outside1 (200.169.226.169): Normal (Monitored) Interface outside2 (189.43.119.29): Normal (Monitored) slot 1: empty Stateful Failover Logical Update Statistics Link : failover Management0/0 (up) Stateful Obj xmit xerr rcv rerr General 11868543 1 604633 0 sys cmd 600054 0 600054 0 up time 0 0 0 0 RPC services 0 0 0 0 TCP conn 4588915 0 475 0 UDP conn 2867035 0 1885 0 ARP tbl 3772016 1 2162 0 Xlate_Timeout 0 0 0 0 IPv6 ND tbl 0 0 0 0 VPN IKEv1 SA 508 0 0 0 VPN IKEv1 P2 16 0 0 0 VPN IKEv2 SA 0 0 0 0 VPN IKEv2 P2 0 0 0 0 VPN CTCP upd 0 0 0 0 VPN SDI upd 0 0 0 0 VPN DHCP upd 0 0 0 0 SIP Session 39999 0 57 0 Route Session 0 0 0 0 Logical Update Queue Information Cur Max Total Recv Q: 0 18 617744 Xmit Q: 0 2048 56934494 |
What am I missing?
Thanks
Solved! Go to Solution.
06-07-2011 06:38 AM
Hello,
When you say you configure something, what exactly are you configuring? Does the problem happen with all config lines you've tested or only certain features?
If you are only seeing the problem with access-lists, the problem could be related to:
CSCtn08562 - ASA: Access-list commands are not automatically replicated to Standby
In either case, it would be worth opening a TAC case for this issue so it can be investigated.
-Mike
09-12-2012 01:42 PM
Hello,
How long has this been happening?
Any changes to the config? Any failover scenario on the last days?
We might be hitting this bug CSCua70156
Commands fail to replicate to standby ASA in failover | |
Symptom:Configuration commands entered on the Active ASA fail to show up on the Standby ASA's configuration. "Debug fover sync" and syslogs on the Standby ASA will indicate the Standby ASA actually receives the commands but it fails to take effect in the running-config. Examples of logs and debugs on Standby ASA:%ASA-5-111008: User 'failover' executed the 'logg mon 6' command. fover_parse: parse_thread_helper: Cmd: logg mon 6Conditions:ASAs set up for some sort of failover (Active/Active or Active/Standby). First seen on ASAs running 8.4(2)8.Workaround:Reload Standby ASA |
Regards,
Julio
06-06-2011 08:16 AM
1) Configuration changes are replicated at the time they are made. They are only replicated from Active -> Standby. They are not replicated from Standby -> Active.
2) Saving the configuration with the 'write mem' or 'copy run start' command will be replicated from Active -> Standby, but does not force the rest of the configuration to be replicated. In other words, if you save the configuration on the Active ASA, the Standby ASA will also save its configuration. If, on the other hand, you save the configuration on the Standby unit, the Active unit will NOT save its configuraiton. This is expected behavior.
3) The purpose of the 'write standby' command is to force a config sync from Active to Standby. The only time this should be necessary is if changes were made to the Standby unit to make the configurations out of sync.
Which commands aren't replicating? Are you sure that you are always making changes to your Active ASA?
*Note: If you ever receive this error message, do not make any changes because you are connected to the standby ASA. All changes should be made to the Active ASA ONLY. (regardless of whether the primary or secondary unit is currently active)
brquinn-5550# conf t
**** WARNING ****
Configuration Replication is NOT performed from Standby unit to Active unit.
Configurations are no longer synchronized.
brquinn-5550(config)#
I hope this helps.
Thanks,
Brendan
06-06-2011 01:17 PM
Hi Brendan!
Thanks for your response.
I'm pretty sure I'm making the configs on the active firewall. My test is the following:
- config something;
- save the configuration with "copy run start" to ensure that the configs are being stored;
- run the command fail exec mate show run | inc
...and the results are always the same. The new configs are never there, except when I force the replication by using "write standby".
I have done this setup in a couple of failover pairs, without any problems....
06-07-2011 06:38 AM
Hello,
When you say you configure something, what exactly are you configuring? Does the problem happen with all config lines you've tested or only certain features?
If you are only seeing the problem with access-lists, the problem could be related to:
CSCtn08562 - ASA: Access-list commands are not automatically replicated to Standby
In either case, it would be worth opening a TAC case for this issue so it can be investigated.
-Mike
09-12-2012 12:08 PM
Was this problem ever solved?
I have this identical problem on an ASA 5525. The only way I can get the config on the standby to sync is to issue the "write standby" command on the active.
Thanks.
09-12-2012 12:20 PM
Hello,
What version are you running?
Regards,
09-12-2012 12:22 PM
8.6
09-12-2012 12:27 PM
Hello,
How are you testing this?
Does it happen with any kind of configuration?
09-12-2012 12:39 PM
I created an object on the active, then did a show run on the standby and it does not appear. If I issue a write standby then check again the new configuration appears.
Its not just objects that dont replicate, I tried many other commands. The show failover history does not show any sync errors. The debug fover sync does not show any errors either.
Thanks.
09-12-2012 01:42 PM
Hello,
How long has this been happening?
Any changes to the config? Any failover scenario on the last days?
We might be hitting this bug CSCua70156
Commands fail to replicate to standby ASA in failover | |
Symptom:Configuration commands entered on the Active ASA fail to show up on the Standby ASA's configuration. "Debug fover sync" and syslogs on the Standby ASA will indicate the Standby ASA actually receives the commands but it fails to take effect in the running-config. Examples of logs and debugs on Standby ASA:%ASA-5-111008: User 'failover' executed the 'logg mon 6' command. fover_parse: parse_thread_helper: Cmd: logg mon 6Conditions:ASAs set up for some sort of failover (Active/Active or Active/Standby). First seen on ASAs running 8.4(2)8.Workaround:Reload Standby ASA |
Regards,
Julio
05-11-2017 10:05 AM
For Anyone who might run into that error,
For us it happened when we upgraded our ASA version.
Our Standby Firewall didn't carry over hostscan image and its config, from its primary. Soon as we copied over and configured hostscan, that error went away.
HTH someone.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: