cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2482
Views
0
Helpful
4
Replies

failover ASA,no continuity of service

Mc Nina
Level 1
Level 1

I wish to have your opinion on the configuration of my ASA cluster.
because I am doing a failover, I have servers from the 152.28.0.0/16 server which can no longer reach the internet and also the servers from the DMZ 172.16.1.0/24 lan.

At the ASA configuration level I do not see any problem, the configuration of my cluster seems to be correct and also at the level of the switch ports connected to the ASA.

thanks for help

 

4 Replies 4

Mc Nina
Level 1
Level 1

attached a diagram of my network

Hi,

Can you share the output of your cluster status (show cluster info)? Also,
do you have virtual MAC configured for your interfaces?

**** please remember to rate useful posts

Bonjour,

 

Merci pour votre réponse.
Nous n'avons pas de cluster en place, il n'est pas pris en charge par le modèle 5508. nous avons un HA configuré, en dessous de la configuration et de l'état du HA:

 

ASA-01 / pri / act # show running-config basculement
basculement
unité LAN
interface LAN de basculement principale ASA-GDI-HA GigabitEthernet1 / 8
basculement clé *****
réplication basculement http
lien de ASA-GDI basculement-HA-link GigabitEthernet1 / 7
interface de basculement ip ASA-GDI-HA 192.168.101.252 255.255.255.0 veille 192.168.101.253
interface de basculement ip ASA-GDI-HA-link 192.168.100.252 255.255.255.0 veille 192.168.100.253
pas de basculement en attente de désactivation
ASA -01 / pri / act # failover exec standby show running-config
failover
failover lan unité secondaire
failover LAN interface ASA-GDI-HA GigabitEthernet1 / 8
clé de basculement *****
réplication de basculement http
lien de basculement ASA-GDI-HA-link Interface de
basculement GigabitEthernet1 / 7 ip ASA-GDI-HA 192.168.101.252 255.255.255.0 veille 192.168.101.253
interface de basculement IP ASA- GDI- HA-link 192.168.100.252 255.255.255.0 veille 192.168.100.253
pas de désactivation de l'attente de basculement

 

 

---------------------------------------------

 

ASA-01 / pri / act # affiche l'état de basculement

État Dernière raison de la panne Date / heure
Cet hôte -
Échec IFc actif principal 17:34:57 CEDT 10 août 2020
Autre hôte -
Échec de communication prêt à la veille secondaire 12:17:45 CEDT 12 août 2020

==== État de la configuration ===
Sync Done
Sync Done - STANDBY
==== Communication State ===
Mac set


ASA-01 / pri / act # failover exec standby show état d'échec

État Dernier motif de défaillance Date / heure
Cet hôte -
Échec Ifc prêt pour la veille secondaire 12:07:35 CEDT 12 août 2020
Autre hôte -
Échec de communication actif principal 12:19:04 CEDT 12 août 2020

==== État de la configuration ===
Sync Done
Sync Done - STANDBY
==== Communication State ===
Mac set

 

pas de mac virtuel, les unités passeront le mac selon qu'elles sont Master ou backup


Merci

Hello,

Thank you for your reply.
We do not have a cluster in place, it is not supported by the model 5508. we have an HA configured, below the HA configuration and status:

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2020.08.26 16:22:37 =~=~=~=~=~=~=~=~=~=~=~=
7

State Last Failure Reason Date/Time
This host - Primary
Active Ifc Failure 17:34:57 CEDT Aug 10 2020
Other host - Secondary
Standby Ready Comm Failure 12:17:45 CEDT Aug 12 2020

====Configuration State===
Sync Done
Sync Done - STANDBY
====Communication State===
Mac set


ASA-01/pri/act# show failover state show failover failover exec standby show failover state

State Last Failure Reason Date/Time
This host - Secondary
Standby Ready Ifc Failure 12:07:35 CEDT Aug 12 2020
Other host - Primary
Active Comm Failure 12:19:04 CEDT Aug 12 2020

====Configuration State===
Sync Done
Sync Done - STANDBY
====Communication State===
Mac set


ASA-01/pri/act# failover exec standby show failover stateshow failover state
Failover On
Failover unit Primary
Failover LAN Interface: ASA-GDI-HA GigabitEthernet1/8 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 8 of 310 maximum
MAC Address Move Notification Interval not set
failover replication http
Version: Ours 9.14(1), Mate 9.14(1)
Serial Number: Ours JAD2307019H, Mate JAD202409WJ
Last Failover at: 14:00:00 CEDT Aug 25 2020
This host: Primary - Active
Active time: 95172 (sec)
slot 1: ASA5508 hw/sw rev (3.3/9.14(1)) status (Up Sys)
Interface Internet (92.103.172.222): Normal (Waiting)
Interface Simplivity (0.0.0.0): Normal (Waiting)
Interface VMware-Management-SiteProd (152.29.6.254): Normal (Waiting)
Interface VMware-Management-SitePra (152.29.7.254): Normal (Waiting)
Interface Administration-SiteProd (152.29.8.254): Normal (Waiting)
Interface Administration-SitePra (152.29.9.254): Normal (Waiting)
Interface Serveurs (152.28.10.40): Normal (Waiting)
Interface DMZ (172.16.1.1): Normal (Waiting)
slot 2: SFR5508 hw/sw rev (N/A/6.2.2-81) status (Up/Up)
<--- More --->

ASA FirePOWER, 6.2.2-81, Up, (Monitored)
slot 2: SFR5508 hw/sw rev (N/A/6.2.2-81) status (Up/Up)
ASA FirePOWER, 6.2.2-81, Up, (Monitored)
Other host: Secondary - Standby Ready
Active time: 949 (sec)
slot 1: ASA5508 hw/sw rev (3.3/9.14(1)) status (Up Sys)
Interface Internet (0.0.0.0): Normal (Waiting)
Interface Simplivity (0.0.0.0): Normal (Waiting)
Interface VMware-Management-SiteProd (0.0.0.0): Normal (Waiting)
Interface VMware-Management-SitePra (0.0.0.0): Normal (Waiting)
Interface Administration-SiteProd (0.0.0.0): Normal (Waiting)
Interface Administration-SitePra (0.0.0.0): Normal (Waiting)
Interface Serveurs (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
slot 2: SFR5508 hw/sw rev (N/A/5.4.1-211) status (Up/Up)
ASA FirePOWER, 5.4.1-211, Up, (Monitored)
slot 2: SFR5508 hw/sw rev (N/A/5.4.1-211) status (Up/Up)
ASA FirePOWER, 5.4.1-211, Up, (Monitored)

Stateful Failover Logical Update Statistics
Link : ASA-GDI-HA-link GigabitEthernet1/7 (up)
Stateful Obj xmit xerr rcv rerr
General41799117 0 2211358 0
sys cmd 391049 0 391048 0
<--- More --->

up time 0 0 0 0
RPC services 0 0 0 0
TCP conn 17466273 0 237 0
UDP conn 7305897 0 1423063 0
ARP tbl 16634931 0 396928 0
Xlate_Timeout 0 0 0 0
IPv6 ND tbl 0 0 0 0
VPN IKEv1 SA 0 0 0 0
VPN IKEv1 P2 0 0 0 0
VPN IKEv2 SA 0 0 0 0
VPN IKEv2 P2 0 0 0 0
VPN CTCP upd 0 0 0 0
VPN SDI upd 0 0 0 0
VPN DHCP upd 0 0 0 0
SIP Session 0 0 0 0
SIP Tx 0 0 0 0
SIP Pinhole 0 0 0 0
Route Session 0 0 0 0
Router ID 0 0 0 0
User-Identity 975 0 82 0
CTS SGTNAME 0 0 0 0
CTS PAC 0 0 0 0
TrustSec-SXP 0 0 0 0
IPv6 Route 0 0 0 0
<--- More --->

STS Table 0 0 0 0
Umbrella Device-ID 0 0 0 0

Logical Update Queue Information
Cur Max Total
Recv Q: 0 13 5796166
Xmit Q: 0 36 43362159

ASA-01/pri/act# show failover failover exec standby show failover state
Failover On
Failover unit Secondary
Failover LAN Interface: ASA-GDI-HA GigabitEthernet1/8 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 8 of 310 maximum
MAC Address Move Notification Interval not set
failover replication http
Version: Ours 9.14(1), Mate 9.14(1)
Serial Number: Ours JAD202409WJ, Mate JAD2307019H
Last Failover at: 14:00:51 CEDT Aug 25 2020
This host: Secondary - Standby Ready
Active time: 949 (sec)
slot 1: ASA5508 hw/sw rev (3.3/9.14(1)) status (Up Sys)
Interface Internet (0.0.0.0): Normal (Waiting)
Interface Simplivity (0.0.0.0): Normal (Waiting)
Interface VMware-Management-SiteProd (0.0.0.0): Normal (Waiting)
Interface VMware-Management-SitePra (0.0.0.0): Normal (Waiting)
Interface Administration-SiteProd (0.0.0.0): Normal (Waiting)
Interface Administration-SitePra (0.0.0.0): Normal (Waiting)
Interface Serveurs (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
slot 2: SFR5508 hw/sw rev (N/A/5.4.1-211) status (Up/Up)
<--- More --->

ASA FirePOWER, 5.4.1-211, Up, (Monitored)
slot 2: SFR5508 hw/sw rev (N/A/5.4.1-211) status (Up/Up)
ASA FirePOWER, 5.4.1-211, Up, (Monitored)
Other host: Primary - Active
Active time: 95176 (sec)
slot 1: ASA5508 hw/sw rev (3.3/9.14(1)) status (Up Sys)
Interface Internet (92.103.172.222): Normal (Waiting)
Interface Simplivity (0.0.0.0): Normal (Waiting)
Interface VMware-Management-SiteProd (152.29.6.254): Normal (Waiting)
Interface VMware-Management-SitePra (152.29.7.254): Normal (Waiting)
Interface Administration-SiteProd (152.29.8.254): Normal (Waiting)
Interface Administration-SitePra (152.29.9.254): Normal (Waiting)
Interface Serveurs (152.28.10.40): Normal (Waiting)
Interface DMZ (172.16.1.1): Normal (Waiting)
slot 2: SFR5508 hw/sw rev (N/A/6.2.2-81) status (Up/Up)
ASA FirePOWER, 6.2.2-81, Up, (Monitored)
slot 2: SFR5508 hw/sw rev (N/A/6.2.2-81) status (Up/Up)
ASA FirePOWER, 6.2.2-81, Up, (Monitored)

Stateful Failover Logical Update Statistics
Link : ASA-GDI-HA-link GigabitEthernet1/7 (up)
Stateful Obj xmit xerr rcv rerr
General3016338 0 96725387 52
sys cmd 643202 0 643196 0
<--- More --->

up time 0 0 0 0
RPC services 0 0 0 0
TCP conn 5102 0 33929621 7
UDP conn 1951245 0 14262461 45
ARP tbl 416670 0 47888689 0
Xlate_Timeout 0 0 0 0
IPv6 ND tbl 0 0 0 0
VPN IKEv1 SA 0 0 0 0
VPN IKEv1 P2 0 0 0 0
VPN IKEv2 SA 0 0 0 0
VPN IKEv2 P2 0 0 0 0
VPN CTCP upd 0 0 0 0
VPN SDI upd 0 0 0 0
VPN DHCP upd 0 0 0 0
SIP Session 0 0 0 0
SIP Tx 0 0 0 0
SIP Pinhole 0 0 0 0
Route Session 0 0 0 0
Router ID 0 0 0 0
User-Identity 119 0 1420 0
CTS SGTNAME 0 0 0 0
CTS PAC 0 0 0 0
TrustSec-SXP 0 0 0 0
IPv6 Route 0 0 0 0
<--- More --->

STS Table 0 0 0 0
Umbrella Device-ID 0 0 0 0

Logical Update Queue Information
Cur Max Total
Recv Q: 0 33 104351371
Xmit Q: 0 34 3705393

ASA-01/pri/act# sho

ASA-01/pri/act# show run

ASA-01/pri/act# show running-config fail

ASA-01/pri/act# show running-config failover
failover
failover lan unit primary
failover lan interface ASA-GDI-HA GigabitEthernet1/8
failover key *****
failover replication http
failover link ASA-GDI-HA-link GigabitEthernet1/7
failover interface ip ASA-GDI-HA 192.168.101.252 255.255.255.0 standby 192.168.101.253
failover interface ip ASA-GDI-HA-link 192.168.100.252 255.255.255.0 standby 192.168.100.253
no failover wait-disable

ASA-01/pri/act# show running-config failover failover exec standby show failover show running-config failover
failover
failover lan unit secondary
failover lan interface ASA-GDI-HA GigabitEthernet1/8
failover key *****
failover replication http
failover link ASA-GDI-HA-link GigabitEthernet1/7
failover interface ip ASA-GDI-HA 192.168.101.252 255.255.255.0 standby 192.168.101.253
failover interface ip ASA-GDI-HA-link 192.168.100.252 255.255.255.0 standby 192.168.100.253
no failover wait-disable

ASA-01/pri/act# sho

ASA-01/pri/act# show f urn

ASA-01/pri/act# show urn run

ASA-01/pri/act# show running-config | inc

ASA-01/pri/act# show running-config | include moni
logging monitor informational
logging class auth monitor emergencies trap debugging
monitor-interface VMware-Management-SiteProd
monitor-interface VMware-Management-SitePra
monitor-interface Administration-SiteProd
monitor-interface Administration-SitePra

ASA-01/pri/act#

Thank you

Review Cisco Networking products for a $25 gift card