cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
169
Views
1
Helpful
2
Replies

Cisco FTD HA Peer Failed

suryaaa
Level 1
Level 1

Dear Team, 

We have both FTD 1120 Firewall. Between them HA peer configured. But for some reason we re image the standby firewall. Break the HA on primary firewall for rejoining standby firewall on HA.

But after deploy HA on standby device HA Peer failed.

please check show failover history command on both router 

Primary

==========================================================================

From State                 To State                   Reason

==========================================================================

Not Detected                  Disabled                       No Error

Disabled                        Negotiation                   Set by the config command

                                                                        (failover)

Negotiation                   Just Active                 No Active unit found

Just Active                    Active Drain                No Active unit found

Active Drain                  Active Applying Config     No Active unit found

Active Applying Config     Active Config Applied      No Active unit found

Active Config Applied      Active                     No Active unit found

Active                              Disabled                   Set by the config command

                                                                         (no failover)

Disabled                   Negotiation                Set by the config command

                                                                         (failover)

Negotiation                Just Active                No Active unit found

Just Active                Active Drain               No Active unit found

Active Drain               Active Applying Config     No Active unit found

Active Applying Config     Active Config Applied      No Active unit found

Active Config Applied      Active                     No Active unit found

 

==========================================================================

Secondary :

> show failover history

==========================================================================

From State                 To State                   Reason

==========================================================================

Not Detected               Disabled                   No Error

 

Disabled                   Negotiation                Set by the config command

                                                                  (failover)

Negotiation                Cold Standby               Detected an Active peer

Cold Standby               App Sync                   Detected an Active peer

App Sync                   Sync Config                Detected an Active peer

Sync Config                Sync File System           Detected an Active peer

Sync File System           Bulk Sync                  Detected an Active peer

Bulk Sync                  Standby Ready              Detected an Active peer

Standby Ready              Failed                         Interface check

                                                                        This host:1

                                                                        single_vf: Interface 6

  

2 Replies 2

What yoh meaning re-image 

You use same image as it before issue suddenly occurs?

balaji.bandi
Hall of Fame
Hall of Fame

i would check the cables, make sure HA IP pingble from both the sides.

check both version correct ? is this managed b y FMC or FDM ?

Follow below troubleshooting :

https://www.cisco.com/c/en/us/support/docs/availability/high-availability/217763-troubleshoot-firepower-threat-defense-hi.html

FMC :

https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center-2600/221065-understand-failover-status-messages-for.html

check this post can help you troubleshooting and post more information as asked in that post :

https://community.cisco.com/t5/network-security/ftd-high-availability-standby-failed/td-p/4286890

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card