ASA 5520: adding failover broke SSL VPN and ASDM

Unanswered Question
Aug 26th, 2009

I had a 5520 running for about 2 months and then successfully added a second 5520 in failover mode. I tested the active/standby feature and everything works as advertised. But, I just discovered that I can no longer connect via SSL-VPN or via the ASDM applet. Would this be related to the failover config?

This IOS is 8.2(1), the ASDM is 6.2(1) on both. I also can still SSH into the box.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Paul Carco Thu, 09/03/2009 - 06:14

Comparing the 'sho version" on both boxes are these ASA's identicle ?

""Prerequisites for Active/Standby Failover

Active/Standby failover has the following prerequisites:

•Both units must be identical security appliances that are connected to each other through a dedicated failover link and, optionally, a Stateful Failover link.

•Both units must have the same software configuration and the proper license.

•Both units must be in the same mode (single or multiple, transparent or routed). ""

rafaelpetter Tue, 10/27/2009 - 11:06

I had the same issue with two ASA 5520 in Active/Standby. When the primary firewall goes down, only telnet/ssh access is allowed to the secondary unit. When i try to connect with ASDM applet to the secondary unit, the applet doesnt respond.

I discovered that disabling the web server "no http server enable" and then enabling "http server enable" we can connect to the secondary unit again like the primary unit before.

This is a bug, maybe?

murray-davis Tue, 10/27/2009 - 12:00

Thank you, Rafael

I forgot to update my post when I solved the problem. Thank you for your response. My solution was different. Here is what happened. In order to connect via ssh or ASDM, you need to have the "anyconnect" pkg installed on your box. I had this image on the primary unit, but not on the secondary. So, when the secondary fired up by itself and then took over the primary role and then the old primary fired up, the new primary removed "anyconnect" from the old primary. Solution, add "anyconnect" back onto both units.



This Discussion