cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1207
Views
0
Helpful
3
Replies

Understanding OSPF failover on Cisco ASA

Jputhusseril
Level 1
Level 1

Hello,

  Need your help. I have Active/Standby ASAs in my data center that is participating in OSPF. Question is we have to test failover between HA. From what I read people are having anywhere between 5-10sec outage during failover because of OSPF convergence. Someone suggested turning on "NSF CISCO" under ospf process. Can find any good info on this how it works on the ASA. Anyone have this running if did you have any outage during failover? Also how does NSF work on ASAs. I'm running 9.4.3 code. Any help is greatly appreciated.

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni

Have you got stateful failover configured, to save having to rebuild the OSPF tables?

If you want even faster failover then reduce the timers.  Check out "failover polltime msec ...".

Yes it is configure for stateful failover. I think failover to standby is fine is just rebuilding OSPF on the standby unit which has me concerned. Anyway to make it so we have no downtime or minimal at the least?

Statefull failover does replicate the OSPF routing table.  I have to admit to OSPF always being a bit painful.  Can you change to EIGRP?  It is very fast in this situation.

If you are running 9.4.3 you shouldn't be affected, but this bug is close to what you are describing.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCto62499;jsessionid=4F67E0A7EC38374F9DF02063F7F46B1D

Review Cisco Networking for a $25 gift card