06-07-2016 07:22 AM - edited 03-12-2019 06:02 AM
I have two ASA5525-X in cluster and software module of SourceFire on each of them.
All day long, I have this error: **Interface 'DataPlaneInterface0' is not receiving any packets** and always after 5 minutes **All interfaces are working correctly**! And only on one ASA.
What could be the problem?
06-07-2016 11:45 AM
Hi ,
Generally this error message comes : "Interface DataPlaneInterface0" is expected on standby device because the interface does not receive any traffic. But if you are getting that after 5 mins and it clears up then the Data Plane on ASA is going down . What is the version on ASA and SFR ?
Regards,
Aastha Bhardwaj
Rate if that helps!!!
06-08-2016 12:42 AM
Version of ASA IOS: Cisco Adaptive Security Appliance Software Version 9.2(2)4 (same on both devices)
Versions of SourceFire software module: v5.3.1.6-16 (same on both software modules)
Version of Defense Center: v5.4.1.5-33
I redirected all traffic (#access-list sfr permit any any).
Can you help me with some advice?
11-18-2016 08:21 AM
Hi ,
It is happing with me too, in my case i have two asa5516 in failover, andon FMC both modules are alerting the message :
"interface 'data plane interface 0' is not receiving any packets "
FMC and modules are running version : 6.1.0
Do you have any suggestion to help me?
tks
12-16-2016 08:17 AM
Hi,
me too. I´ve got a 5525x Cluster. I get the messages on both firewalls.
BR
01-02-2017 12:38 AM
I solved the problem... I should say, there was not really a problem. There was simply no traffic traversing the firewall. Its not enough, that the firewall has an interface in a lan segment. The ASA must be the routing device in L3 mode or in transparent mode, a "bump in the wire". You must at least send a copy of a packet to the sfr module.
BR
02-28-2017 09:27 AM
Running 6.1 on 2 ASA 5515-X's and just started seeing this behavior. If I failover to the standby unit the alert goes away, but shouldn't the original primary throw the same alert if it's not the active device? Something seems wonky.
03-01-2017 01:10 AM
Does it suddenly happen or did you change anything? Do you have your health policy only active for one device? Or do you have different health policies active for the sfr modules?
For my Standby ASA SFR Module I configured a separate Policy where I disabled Interface Status monitoring. If now my primary firewall fails and the secondary takes over I would not see Messages about the Dataplane Interface, even it is inactive. If my primary firewall then would be back online again, I should get the same messages again, as no Data is passing that Interface.
12-28-2016 10:32 PM
See 'Redirect Traffic to the SFR Module' of this link
http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html
forward the ASA traffic to firepower module, the error can be fixed.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide