Hi Mvandorp! Unfortunately there is no preemption mechanisam available for ASA Redundant interface the only option is to use the command redundant-interface redundant 1 active-member in order to make the Primary Interface active again. To check the details refer to the following URLs: http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_start.html#wp1062371 http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/intrface.html#wp1062296 HTH
... View more
Dear Ashish, Thank You for sharing this useful information. I have written an EEM script that is using IP SLA but I have some doubts about it, weather it will work in Production the way I preceives it. Before I share my configuration let me breifly describe what I am trying to accomplish. I have 2 ASA 5585 at the Primary Site which is the Data Center and both firewalls are connected to 2 6506E which are operating in VSS Mode.VSS at the Data Center site is connected upstream to the Aggregation Router that is connected with Multiple Branch Routers via GRE Tunnels.The routes are being exchanged between Aggregation Router and VSS via ospf.At VSS we have Static Routes point to primary firewall that is in Active Mode (2nd Firewall is in Standby Mode). Now the Same Exact Topology exists the Disaster Recovery Site. 2 6506 E are operating in VSS Mode. VSS ports at DR Site used to connect with Primary Firewall are in Shutdown Mode but on the end of the link at Firewall the ports are in no shut mode.Customer is using same exact private RFC 1918 address at both sites Data Center and Disaster Recovery Site. Both sites are connected to Each Other Via Nexus 5K Extended Reach Fiber Link.Also VSS at the Data Center site and Disaster Recovery Site are also connected with extended reach link that running ospf on it. Now in the even if both Firewalls Primary and Seondary goes down at Data Center Site I want VSS Ports at the Disaster Recover site that is connected to Firewall at Disaster Recover Site should go to no shutdown mode and when any of the Firewall at Data Center Site becomes available again I want VSS ports at the Disaster Recovery site should go back to shutdown mode.To acheive this I have written the EEM in conjuction with IP SLA. Could You Please spare some time can validate if this is going to work. Your assistance in this will be highly appreciated. Configuration of the Failover In The Event Of Wan Link Failure at DC Site Configuration at the DR VSS Switch IP SLA To Monitor The Data Center Primary Firewall CORE-DC-FW01 Outside Interface Ip sla 1 Icmp-echo x.x.x.x (Pinging outside interface ip address of the Primary Firewall CORE-DC-FW01) timeout 500 frequency 3 ip sla schedule 1 life forever start-time now track 1 ip sla 1 reachability delay down 8 up 10 EEM Script event manager applet FAILOVERTODR event track 1 state down action 1.0 cli command "enable" action 1.1 cli command “config t” action 1.2 cli command “interface tengigabitethernet 1/2/5 ” (We are brining up the DR VSS 1st Interface that is connected with CORE-DR-FW01) action 1.3 cli command “no shutdown” action 1.4 cli command “exit” action 1.5 cli command “interface tengigabitethernet 2/2/5 ” (We are brining up the DR VSS 2nd Interface that is connected with DR CORE-DR-FW01) action 1.6 cli command “no shutdown” action 1.7 syslog msg “Interface tengigabitethernet 1/2/5 and tengigabitethernet 2/2/5 were brought up via EEM” event manager applet FAILOVERTODC event track 1 state up action 1.0 cli command "enable" action 1.1 cli command “config t” action 1.2 cli command “interface tengigabitethernet 1/2/5 ” (We are shutting down the DR VSS 1st Interface that is connected with DR CORE-DR-FW01) action 1.3 cli command “shutdown” action 1.4 cli command “exit” action 1.5 cli command “interface tengigabitethernet 2/2/5 ” (We are Shutting Down the DR VSS 2nd Interface that is connected with DR CORE-DR-FW01) action 1.6 cli command “shutdown” action 1.7 syslog msg “Interface tengigabitethernet 1/2/5 and tengigabitethernet 2/2/5 were Shutdown via EEM” Furhter will the 2nd EMM script will iterate and can create Loops or will it have any negative impact on the device it is configured on. Looking forward for your reply. Thanks, Regards, Usman.
... View more