Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA Firewall Failover Issue.

Hi......!

I am having two ASA 5520 firewalls which are configured as Failover, but from two days back my second firewall (Stand by) is changing its state,

Due to which my core switches (4506-E) are changeing there status in HSRP.......!

Please see the below log from my ASA

Sep 02 2013 09:21:47: %ASA-1-105005: (Secondary) Lost Failover communications with mate on interface inside

Sep 02 2013 09:21:47: %ASA-1-105008: (Secondary) Testing Interface inside

Sep 02 2013 09:21:48: %ASA-1-105009: (Secondary) Testing on interface inside Passed

Sep 02 2013 09:23:12: %ASA-1-105005: (Secondary) Lost Failover communications with mate on interface inside

Sep 02 2013 09:23:12: %ASA-1-105008: (Secondary) Testing Interface inside

Sep 02 2013 09:23:13: %ASA-1-105009: (Secondary) Testing on interface inside Passed

any one can tell me what can i do for this.....and how can i find out solution for this problem..

Thanks & Regards

Khaja Naseer Uddin

  • Security Management
2 REPLIES
Hall of Fame Super Silver

ASA Firewall Failover Issue.

It appears you may be using the inside interface also as failover link and that link (to the secondary unit) is having issues. Does the port on the switch it connects to show the link as going up and down? If so, it is most likely a cabling issue (bad connection, damaged cable etc.)

Also, best practice is to dedicate an interface for failover and connect the ASAs directly via that (or via a reliable single switch).

New Member

Re: ASA Firewall Failover Issue.

Hi Mr. Marvi Rhoads........!

Thanks for your answer and time.....

Actually i am having two ASA 5520 which are configured as Active/Standby Failover.....

From ASA-1 and ASA-2 three cable are connecting to 2 separate a 2960 G(8ports) switch and there two 2960G switch are connected through a single cable.....

In my setup we are using 2 4506E switches which are running HSRP.

I am observing this issue on both ASA-2 and core switch-2 (4506E)...from ASA i have given log and like this same in switch also HSRP is getting active and again it is going in stand by mode.....where as there is no log in core switch 1 which is running fine.......please help me to understand and resolve this issue.

474
Views
0
Helpful
2
Replies
This widget could not be displayed.