cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1592
Views
0
Helpful
9
Replies

ASA failover issue

gavin han
Level 1
Level 1

Hi,

I've configured two ASA's in failover mode as follow:

primary ASA:

failover
failover lan unit primary
failover lan interface FAIL GigabitEthernet0/3
failover link FAIL GigabitEthernet0/3
failover interface ip FAIL 10.1.9.24 255.255.255.248 standby 10.1.9.25

secondary ASA:


failover
failover lan unit secondary
failover lan interface FAIL GigabitEthernet0/3
failover link FAIL GigabitEthernet0/3
failover interface ip FAIL 10.1.9.24 255.255.255.248 standby 10.1.9.25

I'm having a problem here - failover is not working. failover works right after I reload secondary ASA (sh failover command shows primary is "active" while secondary is "active standby") but failover doesn't work after some time (less than a minute), i don't get any message if I do "debug fover cable".

what could be the problem.

thanks...

9 Replies 9

Jennifer Halim
Cisco Employee
Cisco Employee

Can you please share the following information from both ASA:

show failover

show int ip brief

Also when you mention failover is not working, how do you test the failover?

Hi Jennifer,

following is the output from primary ASA:

ASA1# sh failover
Failover On
Failover unit Secondary
Failover LAN Interface: FAIL GigabitEthernet0/3 (up)
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 4 of 160 maximum
Version: Ours 8.4(1), Mate 8.4(1)
Last Failover at: 15:30:14 UTC Mar 11 2011
        This host: Secondary - Failed
                Active time: 0 (sec)
                slot 0: ASA5520 hw/sw rev (2.0/8.4(1)) status (Up Sys)
                  Interface outside (172.5.4.51): No Link (Waiting)
                  Interface inside (192.168.95.22): No Link (Waiting)
                  Interface DMZ (10.122.0.2): No Link (Waiting)
                  Interface management (0.0.0.0): No Link (Waiting)
                slot 1: ASA-SSM-4GE hw/sw rev (1.0/1.0(0)10) status (Up)
        Other host: Primary - Active
                Active time: 11001 (sec)
                slot 0: ASA5520 hw/sw rev (2.0/8.4(1)) status (Up Sys)
                  Interface outside (172.17.40.50): No Link (Waiting)
                  Interface inside (192.168.95.21): No Link (Waiting)
                  Interface DMZ (10.122.0.1): No Link (Waiting)
                  Interface management (192.168.1.1): Normal (Waiting)
                slot 1: ASA-SSM-4GE hw/sw rev (1.0/1.0(0)10) status (Up)

Stateful Failover Logical Update Statistics
        Link : FAIL GigabitEthernet0/3 (up)
        Stateful Obj    xmit       xerr       rcv        rerr
        General         152        0          152        1
        sys cmd         152        0          152        0
        up time         0          0          0          0
        RPC services    0          0          0          0
        TCP conn        0          0          0          0
        UDP conn        0          0          0          0
        ARP tbl         0          0          0          1
        Xlate_Timeout   0          0          0          0
        IPv6 ND tbl     0          0          0          0
        VPN IKEv1 SA    0          0          0          0
        VPN IKEv1 P2    0          0          0          0
        VPN IKEv2 SA    0          0          0          0
        VPN IKEv2 P2    0          0          0          0
        VPN CTCP upd    0          0          0          0
        VPN SDI upd     0          0          0          0
        VPN DHCP upd    0          0          0          0
        SIP Session     0          0          0          0
        Route Session   0          0          0          0

        Logical Update Queue Information
                        Cur     Max     Total
        Recv Q:         0       16      2971
        Xmit Q:         0       1       153
ASA1# sh int ip b
Interface                  IP-Address      OK? Method Status                Protocol
GigabitEthernet0/0         172.5.4.51    YES CONFIG down                  down
GigabitEthernet0/1         192.168.95.22  YES CONFIG down                  down
GigabitEthernet0/2         10.122.0.2      YES CONFIG down                  down
GigabitEthernet0/3         10.1.9.25  YES unset  up                    up
Internal-Data0/0           unassigned      YES unset  administratively down up
Management0/0              unassigned      YES CONFIG down                  down
GigabitEthernet1/0         unassigned      YES unset  administratively down down
GigabitEthernet1/1         unassigned      YES unset  administratively down down
GigabitEthernet1/2         unassigned      YES unset  administratively down down
GigabitEthernet1/3         unassigned      YES unset  administratively down down
Internal-Data1/0           unassigned      YES unset  up                    up

maybe itsn't working because other interfaces are down except g0/3 (failover interface - this is up)?

by testing failover i meant to say::

whey secondary boots up and if i do "failover active" on secondary then it becomes active initial...then if i do "sh failover" after some time then it says primary:active...secondary:FAIL.

can u advise what problem could be.

Thanks....

Jennifer Halim
Cisco Employee
Cisco Employee

Actually, that is the output from "secondary" ASA, not primary as stated.

And yes, you are absolutely correct, none of the interfaces are actually UP, hence it fails because your interface policy for failover says 1, so when 1 of the routed interface (except gig0/3 coz this is the failover interface) is down, it will trigger a failover.

Actually looking closely, realise that none of the interfaces are actually UP

Thanks...so failover will work correctly if one of the interface of both ASA say g0/0 stays up all the time?

Thanks

OK, for testing purposes, you should disable the monitor interface command on all interfaces so it doesn't monitor the interface.

And no, the policy says, if 1 interface fails, then performs the failover (you can change this to 2 or 3 interfaces fail, up to you). So you will need to have all the interfaces UP as per your current configuration because 1 interface fail will trigger the failover.

For testing purposes, just disable monitoring the interfaces to keep the failover at its correct state:

no monitor-interface outside

no monitor-interface inside

no monitor-interface DMZ

no monitor-interface management

When you are ready for production, and all interfaces are connected, you can re-enable it.

Message was edited by: Jennifer Halim

Thanks...

how about those admin down interfaces? do i have to take them out from the monitoring too?

you said "And no, the policy says, if 1 interface fails, then performs the failover  (you can change this to 2 or 3 interfaces fail, up to you). So you will  need to have all the interfaces UP as per your current configuration  because 1 interface fail will trigger the failover." -> how do i change it from 1 to 3?

thanks ,,,

Admin down interfaces as long as you haven't configured the name, ip address, and security level, it's ok.

Only those interfaces which are listed in the "show failover" output.

cool Thanks Jennifer...I'll check it out

Cheers, pls kindly mark the post as answered if you have no further question. Thank you.

Review Cisco Networking for a $25 gift card