cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
838
Views
0
Helpful
2
Replies

Standby ASA reloaded while failover link down

plwalsh
Level 1
Level 1

Hi,

The failover link between our active-standby ASA installation broke. The active remained active and the standby remained standby initially. After 90 minutes the standby ASA reloaded. There was no crash file generated, no logs stating a reason for the reload.

When the standby unit returned to service it could not detect the active ASA, assumed the active role and voilá, split brain.

Can anyone tell me if a reload is expected behaviour for an active-standby installation with a broken failover link?

Regards,

P Walsh

1 Accepted Solution

Accepted Solutions

patoberli
VIP Alumni
VIP Alumni

This is the expected behaviour after a reboot with broken failover link. I recommend you to set a standby IP address on at least one interface, that way the ASA can use the "normal" network link as a backup failover link, in case the failover cable has a fault.

See table 7.2 for details:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html#81491

View solution in original post

2 Replies 2

patoberli
VIP Alumni
VIP Alumni

This is the expected behaviour after a reboot with broken failover link. I recommend you to set a standby IP address on at least one interface, that way the ASA can use the "normal" network link as a backup failover link, in case the failover cable has a fault.

See table 7.2 for details:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html#81491

Thank you for that information. It verifies that with the failover link unavailable, both units are expected to be active after an unplanned reload.

Review Cisco Networking for a $25 gift card