03-03-2018 03:10 PM - edited 02-21-2020 07:28 AM
Hi All ,
I have a pair of Cisco ASA 5525-X, in HA. The have 9 context's on them. when in active on the primary everything works fine but when I do no failover active, ie the standby then becomes active, one of the contexts websites stop working. from the ASA you can ping both up and down ie the the real server of the website and to the default gateway of the context. I have compared running configurations when both primary and standby are in active and all look the same. all ports seem up and as I can ping up and down it sees not to be that?
Any ideas please?
Thanks
03-03-2018 11:21 PM
Hello,
Since this is happening when secondary device becomes active, I am suspecting to be an arp issue. The only we can fix this is to let the issue happen in a downtime.
Syslogs, interface level captures (ingress and egress) and debug arp output while you try to access the website. It will help us in identifying the root cause.
One thing you can check when you failover is to check the arp entry against the website NATted ip on the firewall. This needs to check on the gateway device. This should be same as the one present now corresponding to the primary device.
HTH
AJ
03-05-2018 12:49 AM
03-05-2018 01:04 AM
Hello,
So, no issue should be happening from the ASA or Checkpoint perspective. The ASA works is that it will send a grat arp once failover happens, hence updating the connected switch ports so that the traffic can be sent accordingly. You can check the switch config to make sure that there is no spanning tree config on those ports and they are configured as edge ports.
Other than that, since we can not have maintenance window, I am out of ideas :(
Regards,
AJ
03-05-2018 01:10 AM
03-07-2018 02:18 AM
03-07-2018 02:25 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide