cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3446
Views
0
Helpful
9
Replies

Cisco ASA 5520 failover

zeeahmed123
Level 1
Level 1

Hi All,

Please can someone help with a failover issue that I ahve and Ijust cant get my head round it..

I have two sites connected via 10G LES link and I have a Cisco ASA 5520 at each site. One of the Sites is the DC and the other is our DR site.

I have configured failover for the Cisco ASA firewalls and would like the node in the DC to be the active firewall. However when I make the the DC node the active firewall it keeps failing over to the secondary node at the DR site. I have changed the failover parameters from milliseconds to seconds and even used the maximum parameters in terms of polling and failover but I still get the same issue. I have also stated that failover should occur if 50% of the interfaces fail, but that too has not solved the issue. We have plenty of bandwidth between the two sites (10Gig) so i dont understand why the firewalls keep failing over. I have tried many times to manually force the node in the DC to be the primary active one but it kjeeps failing over to the DR site.. The Interface used for the failover is a gig interface; I have a separate VLAN configured on the core switches for failover and the failover interfaces are the only interfaces that reside in this VLAN..

Looking at the logs it states the follwoing:

From State                 To State                   Reason
==========================================================================
09:01:53 GMT/BDT Aug 12 2011
Active Applying Config     Active Config Applied      Other unit wants me Active

09:01:53 GMT/BDT Aug 12 2011
Active Config Applied      Active                     Other unit wants me Active

09:04:49 GMT/BDT Aug 12 2011
Active                     Standby Ready              Set by the config command

09:07:51 GMT/BDT Aug 12 2011
Standby Ready              Just Active                Other unit wants me Active

09:07:51 GMT/BDT Aug 12 2011
Just Active                Active Drain               Other unit wants me Active

09:07:51 GMT/BDT Aug 12 2011
Active Drain               Active Applying Config     Other unit wants me Active

09:07:51 GMT/BDT Aug 12 2011
Active Applying Config     Active Config Applied      Other unit wants me Active

09:07:51 GMT/BDT Aug 12 2011
Active Config Applied      Active                     Other unit wants me Active

09:45:07 GMT/BDT Aug 12 2011
Active                     Standby Ready              Set by the config command

09:48:09 GMT/BDT Aug 12 2011
Standby Ready              Just Active                Other unit wants me Active

09:48:09 GMT/BDT Aug 12 2011
Just Active                Active Drain               Other unit wants me Active

09:48:09 GMT/BDT Aug 12 2011
Active Drain               Active Applying Config     Other unit wants me Active

09:48:09 GMT/BDT Aug 12 2011
Active Applying Config     Active Config Applied      Other unit wants me Active

09:48:09 GMT/BDT Aug 12 2011
Active Config Applied      Active                     Other unit wants me Active

09:59:39 GMT/BDT Aug 12 2011
Active                     Standby Ready              Set by the config command

10:02:41 GMT/BDT Aug 12 2011
Standby Ready              Just Active                Other unit wants me Active

10:02:41 GMT/BDT Aug 12 2011
Just Active                Active Drain               Other unit wants me Active

10:02:41 GMT/BDT Aug 12 2011
Active Drain               Active Applying Config     Other unit wants me Active

10:02:41 GMT/BDT Aug 12 2011
Active Applying Config     Active Config Applied      Other unit wants me Active

10:02:41 GMT/BDT Aug 12 2011
Active Config Applied      Active                     Other unit wants me Active

==========================================================================

My failover confi is as as follows:

BEDFORDASA# sh run fail

failover

failover lan unit secondary

failover lan interface FAILOVER GigabitEthernet0/3

failover polltime unit 15 holdtime 45

failover polltime interface 15 holdtime 75

failover interface-policy 50%

failover key *****

failover replication http

failover link FAILOVER GigabitEthernet0/3

failover interface ip FAILOVER 1.1.1.1 255.255.255.252 standby 1.1.1.2

Any help advice will be much appreciated..

regards