Friday, May 31, 2019

Firepower /w ASA Failover issue

Hello,

For two days now our failover lan interface has gone down/down. I fixed it yesterday by changing the interface from e1/12 to e1/10 on both members. Has anyone experienced this before? below is a partial output of my config:

Primary:

Test-Cluster# show run failover

failover

failover lan unit primary

failover lan interface LAN_Failover Ethernet1/10

failover key *****

failover replication http

failover link State_Failover Ethernet1/11

failover interface ip LAN_Failover 192.168.195.1 255.255.255.252 standby 192.168.195.2

failover interface ip State_Failover 192.168.195.5 255.255.255.252 standby 192.168.195.6

Test-Cluster# show failover

Failover On

Failover unit Primary

Failover LAN Interface: LAN_Failover Ethernet1/10 (Failed - No Switchover)

Reconnect timeout 0:00:00

Unit Poll frequency 1 seconds, holdtime 15 seconds

Interface Poll frequency 5 seconds, holdtime 25 seconds

Interface Policy 1

Monitored Interfaces 4 of 1043 maximum

MAC Address Move Notification Interval not set

failover replication http

Version: Ours 9.8(4), Mate 9.8(4)

Last Failover at: 11:40:53 EDT May 30 2019

This host: Primary - Active

Active time: 83122 (sec)

slot 0: FPR-2140 hw/sw rev (49.46/9.8(4)) status (Up Sys)

Interface TestASA (10.55.58.1): Normal (Waiting)

Interface outside (omitted): Normal (Waiting)

Interface inside (192.168.1.1): Link Down (Shutdown)

Interface management (192.168.45.1): Link Down (Shutdown)

Other host: Secondary - Failed

Active time: 2660 (sec)

slot 0: FPR-2140 hw/sw rev (49.46/9.8(4)) status (Unknown/Unknown)

Interface TestASA (10.55.58.2): Unknown (Monitored)

Interface outside (omitted): Unknown (Monitored)

Interface inside (0.0.0.0): Unknown (Waiting)

Interface management (0.0.0.0): Unknown (Waiting)

Secondary:

Test-Cluster# show run failover

failover

failover lan unit secondary

failover lan interface LAN_Failover Ethernet1/10

failover key *****

failover replication http

failover link State_Failover Ethernet1/11

failover interface ip LAN_Failover 192.168.195.1 255.255.255.252 standby 192.168.195.2

failover interface ip State_Failover 192.168.195.5 255.255.255.252 standby 192.168.195.6

Test-Cluster# show failover

Failover On

Failover unit Secondary

Failover LAN Interface: LAN_Failover Ethernet1/10 (Failed - No Switchover)

Reconnect timeout 0:00:00

Unit Poll frequency 1 seconds, holdtime 15 seconds

Interface Poll frequency 5 seconds, holdtime 25 seconds

Interface Policy 1

Monitored Interfaces 4 of 1043 maximum

MAC Address Move Notification Interval not set

failover replication http

Version: Ours 9.8(4), Mate 9.8(4)

Last Failover at: 09:56:15 EDT May 31 2019

This host: Secondary - Active

Active time: 335 (sec)

slot 0: FPR-2140 hw/sw rev (49.46/9.8(4)) status (Up Sys)

Interface TestASA (10.55.58.1): Normal (Waiting)

Interface outside (omitted): Normal (Waiting)

Interface inside (192.168.1.1): Link Down (Shutdown)

Interface management (192.168.45.1): Link Down (Shutdown)

Other host: Primary - Standby Ready

Active time: 29152 (sec)

slot 0: FPR-2140 hw/sw rev (49.46/9.8(4)) status (Unknown/Unknown)

Interface TestASA (10.55.58.2): Unknown (Monitored)

Interface outside (omitted): Unknown (Monitored)

Interface inside (0.0.0.0): Link Down (Shutdown)

Interface management (0.0.0.0): Link Down (Shutdown)



No comments:

Post a Comment