cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
285
Views
5
Helpful
1
Replies

Why failover could not occur after outside/inside interface are shut down in ASA failover ?

wfqk
Level 5
Level 5

Hi, I configured two ASA 5540 as failover. It looks like that Inside interface and Outside interface are already monitored by default. In spite of this, the ASA do not failover after I shut down the both Inside and Outside interface in primary ASA? Please see it below, Any expert can give some suggestion ? Thank you.



ASA1/pri/act(config-if)# sh fail
Failover On 
Failover unit Primary
Failover LAN Interface: LAN-FAIL GigabitEthernet2 (up)
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 2 of 60 maximum
Version: Ours 8.4(2), Mate 8.4(2)
Last Failover at: 23:40:04 UTC May 17 2015
        This host: Primary - Active 
                Active time: 131 (sec)
                  Interface outside (15.1.1.5): Link Down (Monitored)
                  Interface inside (25.1.1.5): Normal (Monitored)
        Other host: Secondary - Standby Ready 
                Active time: 599 (sec)
                  Interface outside (15.1.1.6): Link Down (Monitored)
                  Interface inside (25.1.1.6): Normal (Monitored)

Stateful Failover Logical Update Statistics
        Link : LINK-FAIL GigabitEthernet3 (Failed)
        Stateful Obj    xmit       xerr       rcv        rerr      
        General         0          0          0          0         
        sys cmd         0          0          0          0        

1 Reply 1

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

This is expected. For failover to occur on ASA device , an interface should be UP on one Unit and DOWN on the other one.

I think you are trying to sut the interface on the ASA device which gets replicated to the standby and the failover does not occur.

try shutting don the switchport connected to on the ASA units interface and i think that will trigger the failover.

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking for a $25 gift card