03-09-2017 11:20 AM - edited 03-12-2019 02:02 AM
Hello,
Need your help. I have Active/Standby ASAs in my data center that is participating in OSPF. Question is we have to test failover between HA. From what I read people are having anywhere between 5-10sec outage during failover because of OSPF convergence. Someone suggested turning on "NSF CISCO" under ospf process. Can find any good info on this how it works on the ASA. Anyone have this running if did you have any outage during failover? Also how does NSF work on ASAs. I'm running 9.4.3 code. Any help is greatly appreciated.
03-10-2017 07:29 PM
Have you got stateful failover configured, to save having to rebuild the OSPF tables?
If you want even faster failover then reduce the timers. Check out "failover polltime msec ...".
03-13-2017 06:57 AM
Yes it is configure for stateful failover. I think failover to standby is fine is just rebuilding OSPF on the standby unit which has me concerned. Anyway to make it so we have no downtime or minimal at the least?
03-13-2017 10:52 AM
Statefull failover does replicate the OSPF routing table. I have to admit to OSPF always being a bit painful. Can you change to EIGRP? It is very fast in this situation.
If you are running 9.4.3 you shouldn't be affected, but this bug is close to what you are describing.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCto62499;jsessionid=4F67E0A7EC38374F9DF02063F7F46B1D
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide