08-09-2008 12:41 PM - edited 03-11-2019 06:29 AM
Cisco ASA is configured in HA
But unable to ping the internal interface ip of the secondary box from the primary
08-09-2008 02:26 PM
Hi,
One thing to check would be to make sure you have 'icmp permit
Also, check to be sure you have standby IP addresses configured on each interface ('ip address
If you are still having trouble, please post the output of 'show failover' and 'show run icmp'.
-Mike
08-09-2008 09:34 PM
Are you running any dynaminc routing on the box, like OSPF/EIGRP etc.? Neighbor relationships are only formed with the active unit. If the 'source IP' of the machine you are using to telnet to the secondary firewall is not reachable to the firewalll via a static route, you won't be able to telnet/ping.
Regards
Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide