I've a problem with two ASA 5520 configured for statefull failover Active/standby using a VPN l2l connection. I have sent successfully ping packets from the outside lan but if I switch from the failover to standby ASA the ping doesn't work.
This is my failover configuration:
failover lan unit primary
failover lan interface heartbeat GigabitEthernet0/3
failover polltime interface 1 holdtime 5
failover link stateful GigabitEthernet0/2
failover interface ip heartbeat 188.8.131.52 255.255.255.0 standby 184.108.40.206
failover interface ip stateful 220.127.116.11 255.255.255.0 standby 18.104.22.168
hi the answer to ur query is that asa or pix even in the stateful failover configuration doesn;t support passing on stateful information abt icmp. the icmp xlates are not passed on from the active asa to the standy asa.
so after the failover there will be some drops for the new xlates to be created.but then it will start pinging from the new asa also.
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...