07-13-2023 06:45 AM
We have a 5585 pair in active/standby. Each 5585 is directly connected to a Nexus 7k. The 5585's failover link is directly connected via 10g fiber between buildings. I have two new FP4125's that I have created a logical ASA on each one, copied the config and all the contexts over to the logical ASA's, the management context is up and the management standby IP is up, but NONE of the context standby IP's will show up in the 'standby' Nexus 7k, so the standby IP's aren't reachable and causes failover to be broken. TAC doesn't seem to have an idea and wants us to update the Nexus code since we're on 6.2. Anyone else run into this before?
FP4125 version
Version: 2.12(0.498)
Startup-Vers: 2.12(0.498)
ASA Version 9.16.4.19
NX7K System version: 6.2(16)
07-14-2023 08:25 AM
- If same ports are used on the network then clear the arp cache on the involved ports and or clear the arp cache completely for instance on the standby nexus ,
M.
07-14-2023 08:34 AM
context, how you add ASA image into FPR4100?
07-14-2023 03:16 PM
Have you allocated interfaces to the contexts within context configuration in the default context? If yes, then verify if the interfaces are enabled in FXOS.
07-17-2023 06:04 AM
Are you using portchannels on your Nexus interfaces? If so, note that each ASA (primary and secondary) uses separate portchannels to the Nexus cores. While a Nexus portchannel can span two physical devices visa use of vPC, there's no such construct on the ASA (or FTD for that matter).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide