03-10-2008 04:09 AM - edited 03-11-2019 05:14 AM
Hi,
I've a two ASA5510 & configured Active/standby fO configuration in sub interfaces. But this configuration is not working. Please check the both ASA configuration & let me know what changes i have to take.
I've attached the ASA's configuration
Waiting for Valuable reply.
Solved! Go to Solution.
03-12-2008 01:18 AM
Hi,
Glad you got your failover working correctly. As far as I know shutting down an interface via the config will not cause a failover. This is by design.
As far as the firewalls returning to the primary being the active firewall, this will not be done automatically and will require you to force the units back with the failover active or no failover active command depending on whether you connect to the primary or failed unit.
03-10-2008 04:24 AM
Hi,
Did you follow the instructions here:
This gives you step by step instructions for configuring failover.
Good Luck!
03-10-2008 04:47 AM
Hi,
Thanks, i checked that link but still it is not working. Please check "show failover" & "show failover history" in the outputs.
is there any bug on asa 8.0(3) for this issue (failover) ?
03-10-2008 04:59 AM
The two devices have different configs on them.
When you have firewalls in a failover pair, you need to configure the primary firewall fully only, then configure a minimum set of commands on the secondary firewall. The firewalls will then take care of the rest, including config replication etc.
I you imagine you have two blank firewalls in front of you, read the link above and this should help you understand how failover works.
03-11-2008 11:21 PM
Thanks,
I started from the crash everything is working fine even the failover also. I've 7 sub interfaces on inside interface there I configure for A/S failover. I tested Failover with following procedure.
1. If I remove the cable on inside interface (physical interface) then the failover happened to the standby box for all the sub interfaces. If I give the shutdown command on the sub interfaces the failover is not happen? What could be the problem? Will it happen or not?
Please confirm the following point.
1. After the failover If the primary box coming up whether the standby box (which active present) will go to standby by automatically?
2. Or we have to give manually on the primary box will make as active (âfailover active âcommand)?
I've attached my primary & Secondary ASA with this mail. Please check configuration and revert back .
Thanks in advance.
03-12-2008 01:18 AM
Hi,
Glad you got your failover working correctly. As far as I know shutting down an interface via the config will not cause a failover. This is by design.
As far as the firewalls returning to the primary being the active firewall, this will not be done automatically and will require you to force the units back with the failover active or no failover active command depending on whether you connect to the primary or failed unit.
03-13-2008 05:19 AM
Hi,
Thank you for your update...
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: