Failover issue on ASA 5510 with A/S

Answered Question
Mar 10th, 2008

Hi,

I've a two ASA5510 & configured Active/standby fO configuration in sub interfaces. But this configuration is not working. Please check the both ASA configuration & let me know what changes i have to take.

I've attached the ASA's configuration

Waiting for Valuable reply.

I have this problem too.
0 votes
Correct Answer by brettmilborrow about 8 years 9 months ago

Hi,

Glad you got your failover working correctly. As far as I know shutting down an interface via the config will not cause a failover. This is by design.

As far as the firewalls returning to the primary being the active firewall, this will not be done automatically and will require you to force the units back with the failover active or no failover active command depending on whether you connect to the primary or failed unit.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (1 ratings)
Loading.
helponline Mon, 03/10/2008 - 04:47

Hi,

Thanks, i checked that link but still it is not working. Please check "show failover" & "show failover history" in the outputs.

is there any bug on asa 8.0(3) for this issue (failover) ?

brettmilborrow Mon, 03/10/2008 - 04:59

The two devices have different configs on them.

When you have firewalls in a failover pair, you need to configure the primary firewall fully only, then configure a minimum set of commands on the secondary firewall. The firewalls will then take care of the rest, including config replication etc.

I you imagine you have two blank firewalls in front of you, read the link above and this should help you understand how failover works.

helponline Tue, 03/11/2008 - 23:21

Thanks,

I started from the crash everything is working fine even the failover also. I've 7 sub interfaces on inside interface there I configure for A/S failover. I tested Failover with following procedure.

1. If I remove the cable on inside interface (physical interface) then the failover happened to the standby box for all the sub interfaces. If I give the shutdown command on the sub interfaces the failover is not happen? What could be the problem? Will it happen or not?

Please confirm the following point.

1. After the failover If the primary box coming up whether the standby box (which active present) will go to standby by automatically?

2. Or we have to give manually on the primary box will make as active (“failover active “command)?

I've attached my primary & Secondary ASA with this mail. Please check configuration and revert back .

Thanks in advance.

Attachment: 
Correct Answer
brettmilborrow Wed, 03/12/2008 - 01:18

Hi,

Glad you got your failover working correctly. As far as I know shutting down an interface via the config will not cause a failover. This is by design.

As far as the firewalls returning to the primary being the active firewall, this will not be done automatically and will require you to force the units back with the failover active or no failover active command depending on whether you connect to the primary or failed unit.

Actions

This Discussion