cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8734
Views
5
Helpful
1
Replies

ASA: Failover Using Sub Interface = (Not Monitored)?

chrisbicm
Level 1
Level 1

Hello,

I just set up 2 ASA 5520s in an Active/Passive configuration.... I had to use sub-interfaces for my 2 pipes comming into the office for the outside interface. When I do a "Show Failover" command it says (Not Monitored) take a look at the read out. Does anyone know why they arent monitored, and is there a way I can make it so they are?

This host: Primary - Active

Active time: 1627869 (sec)

slot 0: ASA5520 hw/sw rev (1.1/7.0(4)) status (Up Sys)

slot 1: empty

Interface DMZ (10.10.x.x): Normal

Interface Private (192.168.x.x): Normal

Interface Outside1 (66.38.x.x): Normal (Not-Monitored)

Interface Outside2 (64.187.x.x): Normal (Not-Monitored)

Other host: Secondary - Standby Ready

Active time: 233226 (sec)

slot 0: ASA5520 hw/sw rev (1.1/7.0(4)) status (Up Sys)

slot 1: empty

Interface DMZ (10.10.x.x): Normal

Interface Private (192.168.x.x): Normal

Interface Outside1 (66.38.x.x): Normal (Not-Monitored)

Interface Outside2 (64.187.x.x): Normal (Not-Monitored)

Outside1 and Outside2 are sub-interfaces (g0/0.1 and g0/0.2)

Thanks,

Chris

1 Accepted Solution

Accepted Solutions

gfullage
Cisco Employee
Cisco Employee

The "not-monitored" simply means you haven't set these up as failover monitored interfaces, see the monitor-interface command here:

http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_1/cmd_ref/m_711.htm#wp1636148

Note that "Monitoring of physical interfaces is enabled by default; monitoring of logical interfaces is disabled by default.", which is why your DMZ and private int's are being monitored, but your sub-int's are not.

View solution in original post

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

The "not-monitored" simply means you haven't set these up as failover monitored interfaces, see the monitor-interface command here:

http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_1/cmd_ref/m_711.htm#wp1636148

Note that "Monitoring of physical interfaces is enabled by default; monitoring of logical interfaces is disabled by default.", which is why your DMZ and private int's are being monitored, but your sub-int's are not.

Review Cisco Networking products for a $25 gift card