Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

FWSM : Failover Off (pseudo-Standby)

Hello !!!!,

We are running FWSM Firewall Version 3.2(1). In multi context mode with Interchassie (2 boxes of 6509 ) failover

I have FWSM Failover problem.

Primary Box sh failover output

****

This context: Active

Peer context: Failed

Secondary Box shows

*******

Failover Off (pseudo-Standby)

Failover unit Secondary

Failover LAN Interface: faillink Vlan x (up)

Unit Poll frequency 1 seconds, holdtime 15 seconds

Interface Poll frequency 15 seconds

Interface Policy 4

Monitored Interfaces 46 of 250 maximum

failover replication http

Can some one please guide with the

1. reason behind Failover got off on secondary box

2. What can be done to recover from this state.

3 What are the impact of this if not recovered.

Thanks in Advance

Regards

Yogesh

India

1 ACCEPTED SOLUTION

Accepted Solutions

Re: FWSM : Failover Off (pseudo-Standby)

Yes do a 'write mem'. It seems you are missing an IP on the nattest interface and also you are missing vlans Safeco and Bizco on the secondary core switch.

Do a show vlan on the secondary switch and see if these vlans exists and are ACTIVE!

Regards

Farrukh

13 REPLIES

Re: FWSM : Failover Off (pseudo-Standby)

Mostly you have a VLAN mismatch between thet two FWSMs, have a look at this:

http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a0080965dec.shtml#vlan

Regards

Farrukh

Re: FWSM : Failover Off (pseudo-Standby)

Thanks Farrukh for reply,

Have checked & gone through the config & firewall group on core switch.

Vlan config is not mismatch...

Have tried "write standby" on primary box but no use...

please advice

Re: FWSM : Failover Off (pseudo-Standby)

Please check the trunk between the two switches to make sure all these vlans are allowed.

Can you post 'show failover' from both ends?

Regards

Farrukh

Re: FWSM : Failover Off (pseudo-Standby)

Hi,

Etherchannel between both boxes has indentical vlan.

Please find the attached sh fail for both FWSM

Thanks

Yogesh

Re: FWSM : Failover Off (pseudo-Standby)

Your failover is disabled on the secondary unit. It seems you have done some misconfiguration for these two vlans:

project Interface Safeco (10.33.56.15): No Link (Waiting)

project Interface Bizzapps (10.33.60.15): Unknown (Waiting)

They should be 'Normal' if you VLANS are ocnfigured properly.

Also put 'failover' command on secondar box if its not already there.

Regards

Farrukh

Re: FWSM : Failover Off (pseudo-Standby)

Thanks for your valuable inputs.

Now it is sure where the problem is , with above 2 interfaces...

I have gone through configuration of the above mention interfaces & Vlan. Vlan configuration is perfectly right....

Noticed one thing : On Primary FWSM (Admin context)interfaces of the above 2 interface are exist....but if i look in the admin context of Secondary FWSM i do not see those interfaces.....it may be because of why it has status of no link & Unknown...

but wondering how it has like this...vlan's assigned on to both box ,Vlan groups are identical...above interfaces host are accessing resources using FWSM...means interface in Primary providing service & it is working...

Appreciate if you will help me to dig out this issue...

Thanks

Yogesh

Re: FWSM : Failover Off (pseudo-Standby)

Is it possible to post the configuration for the secondary box? and also the

"show run | inc firewall" from both switches. Also make sure the VLANs are created on both switches and the relevant SVIs exist on the firewall.

Regards

Farrukh

Re: FWSM : Failover Off (pseudo-Standby)

Hi,

Yes same have checked about vlan's and SVI ..it looks ok.

Today also i have created new interface on Primary..but it is not replicated to secondary...

Pl find attached output requested.

Regards

Yogesh

Re: FWSM : Failover Off (pseudo-Standby)

Please go to the secondary unit and enter the following commands:

no failover

failover

Regards

Farrukh

Re: FWSM : Failover Off (pseudo-Standby)

Hi Farrukh,

This option looks fine.

Does these commands are service affecting?

Do i have run write standby command after executing above mention commands.

Thanks

Yogesh

Re: FWSM : Failover Off (pseudo-Standby)

Yes do a 'write mem'. It seems you are missing an IP on the nattest interface and also you are missing vlans Safeco and Bizco on the secondary core switch.

Do a show vlan on the secondary switch and see if these vlans exists and are ACTIVE!

Regards

Farrukh

Re: FWSM : Failover Off (pseudo-Standby)

Hello Farrukh ,

Soluation provided by you is worked & failover started sucessfully without any cause to network.......

Manay Many thanks for advice...

Re: FWSM : Failover Off (pseudo-Standby)

No problem at all. I'm glad its working now :)

Regards

Farrukh

2374
Views
10
Helpful
13
Replies