06-20-2014 04:03 AM - edited 03-11-2019 09:21 PM
Hi,
We have two ASA 5520 with failover enabled. Due to the replacement of a wire in the ASA which is active, the standby ASA took over. However, we found out that the VPN connection wasn't available when this ASA was the active one. Which could be the reason?
Thanks in advanced.
Solved! Go to Solution.
06-20-2014 04:34 AM
Make sure that the configuration has been completely synchronized.
Also make sure you have configured the stateful failover link, which synchronizes the VPN connection info.
--
Please remember to select a correct answer and rate helpful posts
06-20-2014 04:34 AM
Make sure that the configuration has been completely synchronized.
Also make sure you have configured the stateful failover link, which synchronizes the VPN connection info.
--
Please remember to select a correct answer and rate helpful posts
06-26-2014 03:27 AM
06-26-2014 03:34 AM
That output is from show version on the ASA. That just shows you the capabilities of the ASA and not what is currently configured. Basically it says that the license you have installed will allow for Active/Active failover.
What type of VPN connection are we talking about (L2L, Remote Access, IPsec, SSL...etc)?
Are both ASAs the same hardware, and software version? do they have the same licenses installed?
--
Please remember to select a correct answer and rate helpful posts
06-26-2014 04:52 AM
The VPN is SSL.
Both ASA have a VPN Plus license and the same version: Cisco Adaptive Security Appliance Software Version 8.0(2), Device Manager Version 6.0(2).
06-27-2014 07:16 AM
could you post a full running configuration of your primary ASA and secondary ASA (remove any passwords or public IPs).
--
Please remember to select a correct answer and rate helpful posts
07-08-2014 04:45 AM
Hi,
Thanks a lot for your suggestions.
We have been checking the show tech command output to find out that the VPN configuration it's not the same in both ASAs. So my doubt now is, why are the configuration changes made in the active ASA not been transferred to the standby ASA? Apparently, It only affects the VPN configuration as I have added new rules to the ASA today and they also appear in the standby ASA.
06-20-2014 04:53 AM
06-20-2014 04:57 AM
That is the secondary ASA, all configuration needs to be done on the primary ASA...but it looks as though you need to configure the stateful failover link.
--
Please remember to select a correct answer and rate helpful posts
06-23-2014 12:35 AM
Hi,
I check the ASDM Help related to configuring failover and it says the following:
If you choose the LAN Failover interface, you do not need to specify the Active IP, Subnet Mask, Logical Name, and Standby IP values; the values specified for the LAN Failover interface are used. So my state failover seems to be right.
The screenshot attached is the primary ASA. In the help says that:
Preferred Role—Specifies whether the preferred role for this security appliance is as the primary or secondary unit in a LAN failover. Therefore, the ASA is the active one but I have selected secondary as that is the role assumed once it fails and the secondary unit takes over.
Are there other options to check?
Thanks.
06-23-2014 07:28 AM
Hi,
I connect to the secondary ASA. The VPN is configured the same way. However, when I checked the failover configuration I get the warning mesage shown in the screenshot attached. The primary ASA is configured the same way but this warning message is not showed in the primary ASA.
I would be very grateful If you could help me.
Thanks.
06-23-2014 01:22 PM
Are the two ASAs running the same hardware, software image and licenses?
The image attached is of your primary/Active firewall...indicated by the selected prefered role <primary>? so you are seeing this error on your primary ASA and not your secondary.
I would suggest removing the failover configuration and then re-applying it. You might also want to consider a reload of the ASA after you have removed the failover configuration...if you are able to do so.
--
Please remember to select a correct answer and rate helpful posts
06-27-2014 07:43 AM
In looking at the screen shot it seems pretty clear that LAN failover is configured but that State failover is not configured (there is no active IP address, no backup IP address, etc for State Failover). And not having stateful failover would prevent VPN failover.
But as I read the original post I am not clear exactly what the problem is. Perhaps it is that VPN sessions do not fail over. But when it says that VPN was not available I wonder if it really means that new VPN sessions could not be established. Perhaps the original poster can clarify this.
Also I am not clear whether the problem with VPN is for site to site VPN or is for Remote Access VPN. Perhaps we could get clarification for that as well?
On the possibility that it might be about Remote Access VPN and that it is that new sessions can not be established I will add one suggestion. Be sure that the files used for VPN are present on the disk of the standby ASA. Since the config does get replicated it is easy to assume that the files get replicated also. But that is not the case. You need to manually copy the files into disk on both ASA.
HTH
Rick
06-27-2014 08:09 AM
I agree that the state failover does look to be configured. Which is the reason I requested for the poster to provide the configuration so that we can fill in the gaps.
07-08-2014 05:19 AM
Thanks for your suggestions.
We are using Remote Access VPN. The problem is that when the standby ASA takes over it's no possible to connect using VPN. However, We have just found out that the VPN configuration is not the same in our ASAs so that's the reason why people cannot connect when the standby change to active.
I don't understand your explanation about state failover. I think it is configured. In fact this information is available in the ASDM help:
I would say that this explanation fits with my screenshot. However, there must be some problem as the VPN configuration is not replicated in both ASAs although when I add a new rule it is replicated to the standby ASA.
I don't understand your last explanation about files needed to get the VPN configuration replicated. How can I check if that files are in both ASAs?
Thanks in advance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide