cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5625
Views
5
Helpful
15
Replies

Firewall failover..

Hi support,

I show you below configration.

Primary configuration.........

failover
failover lan unit primary
failover lan interface failoverlink Management0/0
failover link failoverlink Management0/0
failover interface ip failoverlink 2.2.2.2 255.255.255.0 standby 2.2.2.3
failover group 1
  preempt
  replication http

Secondary Configuration....................

failover
failover lan unit secondary
failover lan interface failoverlink Management0/0
failover link failoverlink Management0/0
failover interface ip failoverlink 2.2.2.2 255.255.255.0 standby 2.2.2.3
failover group 1
  preempt
  replication http

ASA#fsh failover
Failover On
Failover unit Secondary
Failover LAN Interface: failoverlink Management0/0 (Failed - No Switchover)
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 4 of 250 maximum
failover replication http
Version: Ours 8.0(2), Mate 8.0(2)
Group 1 last failover at: 00:19:48 IST May 20 2010

  This host:    Secondary
  Group 1       State:          Active
                Active time:    93 (sec)

                slot 0: ASA5540 hw/sw rev (2.0/8.0(2)) status (Up Sys)
                  admin Interface intranet (10.190.10.1): Normal (Waiting)
                  admin Interface outside (50.4.90.6): Normal (Waiting)
                  admin Interface dmz (192.168.10.1): Normal (Waiting)
                  admin Interface INSIDE (192.168.40.1): Normal (Waiting)
                slot 1: ASA-SSM-20 hw/sw rev (1.0/5.1(6)E1) status (Up/Up)
                  IPS, 5.1(6)E1, Up

  Other host:   Primary
  Group 1       State:          Failed
                Active time:    656 (sec)

                slot 0: ASA5540 hw/sw rev (2.0/8.0(2)) status (Unknown/Unknown)
                  admin Interface intranet (0.0.0.0): Unknown (Waiting)
                  admin Interface outside (0.0.0.0): Unknown (Waiting)
                  admin Interface dmz (0.0.0.0): Unknown (Waiting)
                  admin Interface INSIDE (0.0.0.0): Unknown (Waiting)
                slot 1: ASA-SSM-20 hw/sw rev (1.0/5.1(6)E1) status (Unknown/Unkn                                                                             own)
                  IPS, 5.1(6)E1, Unknown

Stateful Failover Logical Update Statistics
        Link : failoverlink Management0/0 (Failed)
        Stateful Obj    xmit       xerr       rcv        rerr
        General         36         0          645        0
        sys cmd         36         0          36         0
        up time         0          0          0          0
        RPC services    0          0          0          0
        TCP conn        0          0          283        0
        UDP conn        0          0          107        0
        ARP tbl         0          0          219        0
        Xlate_Timeout   0          0          0          0
        SIP Session     0          0          0          0

        Logical Update Queue Information
                        Cur     Max     Total
        Recv Q:         0       25      645
        Xmit Q:         0       1       36

hello can you tell me my below query...
1> why irs shown me waiting.

2>when my one port is gone down its not working to 2nd asa firewall

what i should change in configuration so i get proper result?

15 Replies 15

hi,

I had checked all connectivity and do shut and no shut of my interface then its take live and all port on interfaceare normal state.

Thanks for support

Review Cisco Networking for a $25 gift card