cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1697
Views
0
Helpful
0
Replies

ASA failover tweak

henrikj
Level 1
Level 1

Hi

I have a ASA running a very large config (22000 lines) and around 950 interfaces (via port-channel). It is running on a firepower 4140. The port-channel are two 10G interfaces and the failover link/state is running on its own 10G interface. Http replication is disabled but the failover is done over the build-in vpn capability. I am only monitoring two interfaces in failover configuration.

Load on the port-channel is about 5-6 G, so failover link/state should have plenty of speed.

Everything also seems to be working fine, but when one of the asa is reloaded (or i do a write standby) and is supposed to sync config and go to standby state, there seems to be at timing issue, because(i think) when asa should check the state of all 950 interfaces it seems to take to long time, so the active asa gives up, and restarts failover replication. It does that 5-6 times, before the standby unit goes in "standby ready" state. 

Are there a way to increase this time or any other suggestions ?

 

Output from cli on active unit:

End Configuration Replication to mate, peer taking too long to move to standby state.
Beginning configuration replication: Sending to mate.

 

Output from cli on standby unit:

Communication with other unit become ok
Primary: Switching to Ok for reason Recovered from communication failure.
Beginning configuration replication from mate.

 

Regards Henrik

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card