ASA Failover Pair - Secondary ASA Config Out-of-sync

Unanswered Question
Jan 20th, 2009
User Badges:

Hi, I have a pair of ASA5520's running 7.2(2). I recently had an issue with VPN tunnels on the secondary ASA when a failover happens and the secondary ASA becomes the active firewall. Tunnels were not coming up after the failover, but I didn't see differences in the "show run" output. I ended up with failing over back to the primary ASA and force a config sync using "write standby" command. Then all tunnels were staying up in the subsequent failover back to the secondary ASA. Although the issue seems to be resolve, I'm still not clear what was the cause of out-of-sync configurations on the secondary ASA? Maybe it's a bug with the old code?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
sbilgi Thu, 01/29/2009 - 09:30
User Badges:
  • Silver, 250 points or more

Yes, it's a bug. Take a look at CSCeg41612 - Fail over out of sync syslog


This Discussion