cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2170
Views
5
Helpful
7
Replies

Failover failed in ASA 5510

Hello:

Hope someone can help me in this issue, today I spent several hours in it but I wasn't be able to fix it.

Two ASA 5510 appliances configured for failover through management interface. At the beginning, both were connected to a switch with 2 sub-interfaces in each one, one VLAN for sinchro and the other one for stateful.

As it didn't work I connected both ASA directly configuring only the monitoring interface. I have ping between them, both interfaces are up and I removed the command "management-only" from management. Both have the same license, model, version but always have the same error:

Failover LAN Interface: controlasa Management0/0 (Failed - No Switchover)

Attach the output from the next commands from both ASA:

- show run failover

- show failover

- show version

- show run management 0/0

Hope someone sees what happen...

Many thanks,

Francisco

1 Accepted Solution

Accepted Solutions

what do you mean both interfaces? you have 4 regular interfaces defined (inside,outside, 2xdmz). Check the vlan configuration on those switch ports.

View solution in original post

7 Replies 7

srue
Level 7
Level 7

it looks like neither asa can see the other fully. check your switchport assignments as far as the vlans go.

make sure you interfaces are not shutdown on either one.

Right now two ASA are connected directly, both interfaces are up/up (there is connectivity between them throug ping)

what do you mean both interfaces? you have 4 regular interfaces defined (inside,outside, 2xdmz). Check the vlan configuration on those switch ports.

With both interfaces I mean the management interfaces in the appliances.

Yes, they have 4 interfaces, the primary has all of them connected and up and it's providing connectivity to the customer. The secondary only has connected and up the interface management (connected to the another ASA). I didn't connect the regular interfaces because the failover is not working and I would have duplicity IP's issues

failover's not working because you haven't connected all interfaces on the secondary.

on the secondary there should be NO configuration other than your failover commands and bringing each interface out of the shutdown state.

reset the config on the secondary (wr er) and then copy/paste in the failover config AFTER you've plugged in ALL interfaces.

Ok, many thanks for your help

As you said, the problem was it. The failover is ok now.

Many many thanks!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card