04-11-2023 02:12 PM
Hello,
I have recently implemented HSRP on our Core Switches. The HSRP works when I unplug the ethernet cable to the ASA (Unplug Core Switch 1, network goes down for a second but resumes connection with Core Switch 2 and vice versa). However, the problem is when the power is cut on Core Switch 1, the network completely goes down. Core Switch 1 is set to be the primary for every VLAN (excluding some VLANs that are having issues with HSRP) on the network, and Core Switch 2 is the secondary for the said VLANs.
I have read that it could be spanning-tree configurations so I tried to set the primary and secondary root for the VLANs in the past by setting the priority manually. But that did not work either. I am going to do another test using root primary and root secondary configuration without setting the number manually. Are there any other suggestions or tip on how to troubleshoot this issue?
04-11-2023 02:14 PM - edited 04-11-2023 02:15 PM
I need to check the topology
I remember you you config ASA with stackwise weeks ago ? is it same site ?
04-11-2023 02:22 PM
Yes but we got rid of the Stackwise due to it not being supported on the Cat9500 switches we have.
From the ASA, I am using two interfaces as members of a interface Redundant1. Then from there it goes to the Core Switches and the interfaces are Access Ports using VLAN 40 with an SVI. The HSRP is configured for Core Switch 1 being the primary and Core Switch 2 being the secondary with preempt enabled.
04-11-2023 10:59 PM
I am not sure why it would work when you unplug a cable bit fail if the switch is powered down, Perhaps seeing the current running config of the switches and ASA (or at least the config of the interfaces) might shed some light on this?
04-12-2023 07:15 AM
Any specific configurations that I should be looking for? I am quite stuck because the HSRP configurations are correct and the connection to ASA seems correct as well.
04-12-2023 07:23 AM
NOTE:-
it can issue is ASA keep MAC address of OLD Core,
this can solve via track add to static route and using EEM to clear the ARP table when static add/removing in ASA
MHM
04-12-2023 10:42 AM
Why you make it hard to you'
ASA must use static point to VIP of hsrp
NATing is not issue here.
04-12-2023 10:50 AM
I was thinking maybe it's the traffic getting out that is getting stuck? Traffic coming in is not the issue. The ASA is using static IP (virtual IP from VLAN 40 using .1). But since I have no internet connection maybe some NAT configurations needed to be added? The HSRP configurations look correct. I have the Virutal, Standby priority, standby preempt, version 2 configured on the SVIs (VLANs).
04-12-2023 10:56 AM - edited 04-12-2023 11:00 AM
Which is connect to internet asa or core sw?
If core sw then you need nat hsrp aware.
But to be honest this not make your traffic drop.
04-12-2023 01:05 PM
It goes like this:
Internet>ASA>Core Switch 1 and 2
04-12-2023 01:10 PM
So for NAT there is one inside and one outside' there is no issue as I mention before.
The issue which I thinking about two hours is are there multi hsrp group'
I.e. there one hsrp for asa and there hsrp for hosts??
04-12-2023 01:37 PM
If you are referring to the SVIs having HSRP, yes. I have the HSRP for VLAN 40 which is the for the ASA, and we have HSRP configured for the SVIs for the VLANs on the network.
04-13-2023 02:36 AM
I will make this lab open until we find solution for your issue,
I take time to do lab becuase the L3SW image in GNS3 can not do inter-vlan and so I use NSK instead
anyway
the Issue if the link to MHM-1 is down the traffic shift if the MHM-1 is failed the traffic drop, as I think is the HSRP in both Side.
so when the MHM-1 failed (one of Core SW) check the HSRP of host side not ASA side check if it point to correct MHM-2 or not
04-13-2023 07:11 AM
That what I will be doing this Saturday. I have planned a short down time to cut the power to Core Switch 1 to check on Core Switch 2 to see if the standbys become active on Core Switch 2. If it doesn't then we have an issue with HSRP or the heartbeat connection between Core Switch 1 and 2. Thank you.
04-12-2023 09:54 AM
It is difficult to identify specific configurations because we do not know what the issue is. Perhaps is it some difference in the way that interfaces are configured? Perhaps it is some difference in the way that NAT is configured? Perhaps it is something about the way that redundancy is configured? Perhaps it is because of lack of symmetry in the traffic? I am trying to get more information about the environment and the issue in hope that something will point toward the issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide