cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
761
Views
0
Helpful
1
Replies

ASA5585-X SSP40 Failover Problem

Atasawar1
Level 1
Level 1

I have recently implemented ASA5585-X SFR SSP40 failover. Failover is up interfaces are monitored and configuration is replication and syncing from active to standby pair. Connectivity to core switch Cisco 6807-XL which is VSS pair is as following; 

Firewall#1

Firewall#1: Port Ten0/6 connected to Ten1/2/17 Core1 (Inside Port-channel)

Firewall#1: Port Ten0/7 connected to Ten2/2/17 Core2 (Inside Port-channel)

Firewall#1: Port Ten0/8 connected to Ten1/2/19 Core1 (Outside Interface)

Firewall#1: Port Ten0/9 connected to Ten0/9 Firewall2 (Ten0/9.1 LAN Failover, Ten0/9.2 Stateful Failover) 

Firewall#2

Firewall#2: Port Ten0/6 connected to Ten2/2/20 Core2 (Inside Port-channel)

Firewall#2: Port Ten0/7 connected to Ten1/2/20 Core1 (Inside Port-channel)

Firewall#2: Port Ten0/8 connected to Ten2/2/19 Core2 (Outside Interface)

Firewall#2: Port Ten0/9 connected to Ten0/9 Firewall2 (Ten0/9.1 LAN Failover, Ten0/9.2 Stateful Failover) 

We are running ospf on core switches and ASA Firewall outside interfaces Ten0/8 on both firewalls are also configured in ospf

Firewall1 is primary and Firewall2 is the secondary pair in failover. 

When Primary firewall is active ospf neighborship goes as well as I can not ping the subinterfaces created under inside interface port-channel

when I make my secondary firewall as active ospf neighborship comes up and also I'm able to ping subinterfaces created for my inside networks. 

What could be the problem, is it something to do with port-channel configuration or failover configuration. 

Thank you all in advance for kind response.

Regards,

Asad.

1 Reply 1

Atasawar1
Level 1
Level 1

This is to inform you all if someone wonders that what happened to above-mentioned problem.

There are four ports connecting to core switches from firewalls. I created single port-channel for all four interfaces connecting to all four interfaces two each to respective firewalls and I was facing above mentioned problem but as soon as I created two port-channels for each two interfaces connecting to the respective firewall, everything came up and running. And life is good now 🙂

Review Cisco Networking for a $25 gift card