cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3494
Views
0
Helpful
1
Replies

ASA Failover Pair - Secondary ASA Config Out-of-sync

josephqiu
Level 1
Level 1

Hi, I have a pair of ASA5520's running 7.2(2). I recently had an issue with VPN tunnels on the secondary ASA when a failover happens and the secondary ASA becomes the active firewall. Tunnels were not coming up after the failover, but I didn't see differences in the "show run" output. I ended up with failing over back to the primary ASA and force a config sync using "write standby" command. Then all tunnels were staying up in the subsequent failover back to the secondary ASA. Although the issue seems to be resolve, I'm still not clear what was the cause of out-of-sync configurations on the secondary ASA? Maybe it's a bug with the old code?

Thanks!

1 Reply 1

sbilgi
Level 5
Level 5

Yes, it's a bug. Take a look at CSCeg41612 - Fail over out of sync syslog

Review Cisco Networking products for a $25 gift card