cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
901
Views
0
Helpful
2
Replies

asa failover issue - secondary gets No Failover command

karien.depyper
Level 1
Level 1

Hi,

Anybody has seen this issue, or even better, solved it :-)

We have 2 failover clusters  that works fine for some time
but after a random time (6 to 50 days seen), for an unknow reason, the 'no failover' command shows up in the secondary firewall configuration and it has also the NoFailover prompt.
After that we have 2 active firewalls with the known consequences :-(
We have 2 cisco cases, but Cisco doens't find anything and we are currently waiting for the issue to happen again to take logs.

extra info:
1 cluster  with 8.2.4 soft
1 cluster with 8.0.5.23 soft

thx Karien

2 Replies 2

mirober2
Cisco Employee
Cisco Employee

Hi Karien,

What does 'show failover history' on both units show when the problem occurs? Are there any syslogs generated when the problem happens? These should give you an idea of why failover is getting disabled.

-Mike

Hello again,

Root cause found:

1/ Versions higher then 8.0.4 and 8.2.4 have a change in code, by which low failover timers (msec) and redundant interfaces can cause this issue. I changed failover timers, and it seems solved now.

Before:

failover polltime unit msec 200 holdtime msec 800

failover polltime interface msec 500 holdtime 5

Now:

failover polltime unit 1 holdtime 5

failover polltime interface 1 holdtime 5

2/ failover over management interface is not supported.

Good luck!

Review Cisco Networking for a $25 gift card