cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
780
Views
0
Helpful
3
Replies

Secondary ASA 5550 firewall getting down automatically

gupta.dheeraj
Level 1
Level 1

I am having two ASA 5550 firewall running in active/standby mode. With in last two months our secondary firewall got down automatically 3 times. Firewall is running with IOS version 7.1.2. Kindly help me if any one have faced a similar problem. also suggest how to proceed further troubleshooting because there are not any logs on firewall.

----Dheeraj Gupta

3 Replies 3

Anu M Chacko
Cisco Employee
Cisco Employee

Hi Dheeraj,

Can you specify if the ASA is "rebooting" or "crashing"? It's pretty hard to say why the issue occurs without looking at the "show tech" output. If the ASA is rebooting on its own, it might also be crashing. Check "sh crash" to see if there is any relevant crash recorded.Check the output of "sh failover history" for the time when the issue occured. Or you might be hitting a bug.

If there is a relevant crash file in the flash, I suggest you open a TAC case so that the crash can be decoded and analyzed.

Hope this helps!

Regards,

Anu.

P.S. Please mark the question as answered if it has been resolved. Do rate helpful posts. Thanks.

Hi Anu,

ASA is neither rebooting nor crashing. We have observed after 2-4 weeks its all interfaces are going down ( not any LED status ) only power LED on back side of firewall is glowing and firewall is not comming on console as well. After rebooting it works fine for 2-4 weeks and again problem starts. Please find attached "show Tech".Also there is not any crash info on the device. Now problem is that issue is not persitant and it occurs after 3-4 weeks, so  it is very difficult to come to any conclusion. If you have any suggesstion please suggest how we can proceed further.

Regards

Dheeraj Gupta

Ok

and the syslogs do they tell you anything ?

it does not sound like a hardware error, I would guess at some counter filling up or memory overspilling or something like that.

Either way the version 7.1.2 is very old and there are many many reasons why you would want to exchange that version for a newer one.

i am not saying that you need to go to 8.3 or 8.4 versions, startup easy with 8.2 or something like that.

lots of nice new features that are realy good to have.

Good luck

HTH

Review Cisco Networking for a $25 gift card