cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
10099
Views
0
Helpful
7
Replies

ASA LAN Based Failover not working

central_bank
Level 1
Level 1

Hi,

I have ASA 5510 connected as shown in attached diagram.

Ideally when ASA 1 is active and if I boot Switch-1, ASA-2 shood take over. But that is not happening.

When I boot SW1 , ASA-2 shows "Failover LAN Interface: failover Ethernet0/0 (Failed - No Switchover)" and remains standby.

Failover works properly If ASA-1 boots.

1 Accepted Solution

Accepted Solutions

Hi Shivaji,

Here's how to add a redundant interface:

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1049334

Please read the guidelines for configuring redundant interfaces for failover.

Hope this helps!!

Regards,

Anu

P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.

View solution in original post

7 Replies 7

varrao
Level 10
Level 10

Hi,

Can you provide the configuration for the failover on the devices???

Varun

Thanks,
Varun Rao

Since the failover link is failing. You should restore the failover link as soon as  possible because the unit cannot fail over to the standby unit while the  failover link is down.

Here is a link to document which explains failover actions

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_active_standby.html#wp1079555

Agreed,

But for ASA 2, failure of sw1 is as good as failure of ASA1, hence don't u think, ASA 2 should become active

Hi Shivaji,

Lets say that ASA1 is active and ASA2 is standby. If the sw1 goes down but the other data interfaces of both the devices are up, then the units can still hear each other through those. So, a failover will not happen, the standby will remain standby and traffic through the active will not be affected. This is why you see that behavior.

A switchover will happen if a number of data interfaces are down. This is decided based on interface monitoring tests. But then again, for failover to happen the failover link must be up and functioning well. As a side note, after the fix for the following bug,  failover will happen even if the failover link is down:

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsw37519

Hope this is clear.

Regards,

Anu

P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.

Gr8...I found one doc which says the connectivity I have done is not recommened. We should have seperate switch for failover link.

Also the document says that, we can have two ASA's connecetd directly using cross cable with redundant faiover link.

But I dont knw how to configure the redundant fover link.

Document Link : http://www.cisco.com/en/US/partner/docs/security/asa/asa80/configuration/guide/failover.html

Do you have any idea on this?

Hi Shivaji,

Here's how to add a redundant interface:

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1049334

Please read the guidelines for configuring redundant interfaces for failover.

Hope this helps!!

Regards,

Anu

P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.

Gr8...Thanks

Review Cisco Networking for a $25 gift card