Cannot Access AIP-SSM in Secondary ASA

Answered Question
Sep 29th, 2010

Hello all,

I have a customer with a failover pair of ASAs 8.0, each with an AIP-SSM.  The AIP in the secondary ASA is not accessible via its IP address, so cannot be accessed using IDM or ASDM, or ssh.  It can be accessed by sessioning into the module, and it cannot ping anything outside of it.  The access-list for the relavent interface on the ASA is "any any".

The secondary ASA itself is accessible with ssh and ASDM.

Nearby devices don't get an arp response for the AIP IP address. The access-list in the AIP permits the IP address we are coming from.


Any ideas why we cannot get in?

Thanks,

Paul

I have this problem too.
0 votes
Correct Answer by Jennifer Halim about 6 years 2 months ago

Sorry to ask basic question, but I am assuming that the secondary AIP-SSM port is cabled and connected to the right VLAN (same as what is assigned to the primary AIP-SSM vlan)?

Also, the IP Address assigned to the secondary AIP-SSM module is in the same subnet as the one assigned to the primary AIP-SSM module?

What do you see on the switchport connected to the secondary AIP-SSM module compared to the primary module?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Jennifer Halim Wed, 09/29/2010 - 17:30

Sorry to ask basic question, but I am assuming that the secondary AIP-SSM port is cabled and connected to the right VLAN (same as what is assigned to the primary AIP-SSM vlan)?

Also, the IP Address assigned to the secondary AIP-SSM module is in the same subnet as the one assigned to the primary AIP-SSM module?

What do you see on the switchport connected to the secondary AIP-SSM module compared to the primary module?

wromsait Wed, 09/29/2010 - 17:41

Hi Paul,

I would check to to see what vlan the SSM management port is connected to on the switch side.  If a local device in the same subnet as the SSM is not seeing the arp then it could be a vlan issue. Perhaps the SSM is not in the correct vlan.   Try to trace the SSM management port and see which switch it is connected to.  From the switch, see what vlan the management port is connected to.  From the switch, see if the SSM's mac address is learned on the switch port.  You can get the SSM's mac from the ASA by doing "show module 1 detail".  You can also connect a pc in the same switch and same vlan as the SSM and see if the pc can ping and arp for the SSM.   You can also use the switch SVI to do this ping and arp test.   You can also connect a pc directly to the SSM management port via the cross over cable.  This will rule out if there could be an issue with the management port of the SSM. 

Hope this helps.

paul_murphy Thu, 09/30/2010 - 05:43

Thanks for the replies.

You know how when you get a project handed over to you and it is nearly finished and just few last things to do?  So you make the assumption that all the obvious things are right so any problem found must be complex?

Don't do that.  Check the cable is actually plugged into the management port.

It wasn't.

Actions

This Discussion

Related Content