09-21-2018 06:19 PM - edited 02-21-2020 08:16 AM
Hi All,
We are running ASAs 9.8(2) in Act/Stdby mode. Recently, our primary ASA got rebooted and services got impacted. Upon checking checking failover history, we got the message - Detect service card failure. Upon checking syslogs - we only got 2 messages of significance:
i) Line protocol on interface changed state to down
ii) Line protocol on interface changed state to up
I believe the inside interface went down or something but can someone please explain a bit more in detail about this since we are doing RCA.
1) What's "Detect service card failure" mean?
2) What measures should we take in order to avoid this happening again in future?
I have attached a the failover output file for reference.
Regards,
Abhijit
09-22-2018 02:12 AM
Hello Abhijeet,
The service card refers to any software based IPS module installed in the ASA, for example IPS module. If it fails or it is too busy to respond to the ASA backplane hello packets, it is detected as a failover reason and failover would happen.
The logs from Secondary device are from 13 Sep when I guess that the primary device reloaded, which is normal since it says that it has not heard from mate, and hence it became active. This happened around 21:55 on Sep 13th 2018.
The logs from Primary firewall wherein says service card failed looks like a transition phase message when it was initializing after the ASA reloaded.
The real issue here is on Sep 20th around 12:59 when the interface failed message appears on Primary Firewall and this comes from inside interface. That is where you need to focus apart from the reason behind the reason for primary firewall reload.
Regards,
Ajay
09-24-2018 05:36 PM
Hi Ajay,
Thanks a lot for your inputs. Yes, we do have an IPS module built-in the ASA, though we dont use it.. Can you please let me know if there are any preventive measures, or any commands which we configure to avoid this incident happening again?
Regards,
Abhijit
09-25-2018 02:38 AM
Hello,
If you wish to remove the IPS card from failover monitoring, you can remove the failover monitoring of the IPS module:
no monitor-interface service-module
HTH
AJ
10-21-2022 12:14 AM
Hello Ajay,
I have the same case but I don't have an IPS module within my Cisco ASA and I got random failover with reason:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide