Cisco Firewall :: ASA 5550 - Interface Failover / Interface Goes Down

Mar 18, 2013

I've got a ASA 5550 firewall interface failover issue. (File attached).
when I shut down the inside interface Gi 1/1 of the left firewall(Active firewall), It failed to failover. but when I shut down the Gi 1/12 of the Core 1 switch, The firewall failover very well.
I followed this guide but I was not able to failover. [URL]
how can I configure so that when the Gi 1/1 or Gi 1/0 interface goes down, it can failover ? Code...

View 6 Replies


Cisco Firewall :: ASA 5550 Module 1 Interface

Oct 25, 2011

Is it possible to use ports from 2 SFP and 2 RJ45 Interface on ASA 5550 Module 1.

View 5 Replies View Related

Cisco Firewall :: ASA 5550 Inside Interface Hangs

Apr 24, 2012

the inside interface on our primary ASA seemed to "hang". It dropped all the packets it received. Because the interface didnt go down, failover didn't happen. Device's info;

-Cisco Adaptive Security Appliance Software Version 8.2(3)
-Device Manager Version 6.3(3)
-Hardware:   ASA5550, 4096 MB RAM, CPU Pentium 4 3000 MHz
-Internal ATA Compact Flash, 256MB
-BIOS Flash Firmware Hub @ 0xffe00000, 1024KB
I attached a capture picture shows that traffic didnt go to the roof when the issue happened. Why the interface would "freeze" randomly?

View 1 Replies View Related

Cisco Firewall :: ASA 5550 To Setup Unit / Cannot Configure IP In Interface

Nov 12, 2011

I am normally only doing IOS config. I have little problem when trying to setup this unit.,It boots ASA software 8.0.4 fine.,When i go to enable mode and into configuration mode and try to configure ip on an interface i have a problem.,

ciscoasa(config)# intciscoasa(config)# interface manciscoasa(config)# interface management 0/0ciscoasa(config-if)# ?,Interface configuration commands:  default      Set a command to its defaults  description  Interface specific description  dhcp         Configure parameters for DHCP client  duplex       Configure duplex operation  exit         Exit from,interface configuration mode         Interactive help for interface subcommands  no           Negate a command or set its defaults  shutdown    ,Shutdown the selected interface  speed        Configure speed operationciscoasa(config-if)#

I did try to upload the new software 8.4.2 from rommon using TFTP. ,It boots 8.4.2 fine, but  have same problem as in 8.0.4.,I did try to create a user haveing priv 15 and logging on as that user. It gives the same.,The firewall is not in transparent mode.

View 3 Replies View Related

Cisco Firewall :: ASA 5550 / RFC 1918 - Tunnel Terminates At Outside Interface

Aug 2, 2011

I've recently set up a LAN-2-LAN VPN tunnel to a 3rd party service provider who uses RFC 1918 private addressing internally and cannot perform NAT on their side of the tunnel.  In order to avoid conflicts with our address space I've had to implement DNAT for the address on the 3rd party network that users at my end must access.  The tunnel terminates at my end on the outside interface of an ASA-5550 running 8.4.2.  While the ASA has 8 interfaces at security levels between 0 and 100, DNAT only need occur for traffic flowing from inside (100) to outside (0).

The following (redacted) addressing applies:

Address of the server on the 3rd party provider network:

Mapped address of server as seen on the network at my end:

I've currently implemented DNAT using object NAT as follows:

object network remote-server
nat (outside,inside) static

This works as expected, however in examples and discussion I've seen, it appears that the typical way to configure NAT for this scenario is with manual NAT as follows:

object network remote-server

object network remote-server-mapped

nat (inside,outside) source static any any destination static remote-server-mapped remote-server
Is there any reason why I should consider using the manual NAT method rather than the object NAT method in this scenario?Are there any technical reasons why using object NAT in this manner should be avoided?

View 1 Replies View Related

Cisco Firewall :: ASA 5550 - Configuring Sub-interfaces On Management Interface

Nov 29, 2011

I am currently doing some research (for my employer) into creating multi-context sub-interfaces on a Transparent ASA 5550.
I have not been able to find any details on this subject which state it is or it is not possible. This will be used for Syslog logging.

View 1 Replies View Related

Cisco Firewall :: ASA 5550 Switch - Change Media Type Command On Interface

Oct 12, 2011

I am switching a switch connecting to the ASA5550 tomorrow. My current switch is using fiber connecting to the ASA. The new one only support copper. If I switch between fiber to copper on the ASA (change media-type command on interface) will it cause a down time? I have VPN tunnel on the ASA and don't want the session to reset.

View 2 Replies View Related

Cisco Firewall :: Changing PIX 515E Failover Interface IPs?

Mar 6, 2011

I am looking to change my Failover Int IPs on my PIX 515E Bundle, Cisco PIX Firewall Version 6.3(5)123 with the least impact on the network.
For example:
interface ethernet5 "state"
IP address, subnet mask
 ip address state
 failover ip address state
I want to change these lines to .....
interface ethernet5 "state"
IP address, subnet mask
 ip address state
 failover ip address state

View 3 Replies View Related

Cisco Firewall :: ASA 5540 Redundant Interface Failover

May 8, 2011

I have two ASA 5540s, ver 8.4 configured in Active/Standby failover.I am also using the redundant interface feature for my Inside interface.  Gig0/0 is the active primary and Gig0/1 is standby.
I will activate failover monitoring of the Inside interface using the monitor inside command.
My question concerns the failover monitoring of the redundant interface.  If the gig0/0 connection were to fail would the Gig0/1 interface become Active, AND simultaneously result in a full device failover?
Or, does Gig0/1 of the Inside interface redundant pair simply become active and not change the Inside interface device failover state?  Thus NOT resulting in a device failover.

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Failover - Can't Choose Interface

Dec 14, 2011

I am trying to configure two ASA-5505 as a failover pair. Software 8.2.5 and ASDM Using the wizard i get to step3 .. then nothing happens. Trying direct in asdm but the only interface i can choose is "--None Unnamed-"

View 1 Replies View Related

Cisco Firewall :: ASA 5520 8.4 Failover Interface Testing?

Jan 3, 2012

From ASA 5520 we tested the interface failover it not working even the interface are getting monitor . 
primary is active.
Manually we shut the outside interface of the primary device configuration is getting reflecting in secondary as outside interface shut. Interface failover not happen.
ii All the interface are getting monitor when we gave command sh failover. even though when we shut outside interface failove not happening.
how to do the interface failover in ASA 8.4 version.

View 3 Replies View Related

Cisco Firewall :: Failover ASA 5505 - Setup Second Inside Interface On Firewall?

Feb 19, 2012

I have a Cisco ASA 5505 in our office. We are currently using Interface 0 for outside and 1 for inside. We only have 1 Vlan in our environment. We have two three switches behind the firewall. Today the uplink to Interface 1, to the firewall, on the switch went bad. I want to setup a second inside interface on the firewall and configure it as failover incase this happens again. I want to attach it to the other switch. Can I do this? If so, what do I need to do? would it only be a passive/standby interface?

View 1 Replies View Related

Cisco Firewall :: Failover On ASA5510 - Reason Of Interface Tests

Jun 24, 2011

Do I correctly understand that when two ASA 5510 are in fail over pair, the switchover from primary to secondary if one interface of primary goes down shall happen ONLY if failover link is up? So when the fail over link is down and one interface on primary got down also,  interface tests between the two ASAs still are being done , but secondary SHALL NEVER try to become active.

In this case why to make  tests on data interfaces ? What is the reason to make them? If the knowledge of that some interfaces  of primary became down comes through failover link - no need to make additional interface tests - primary will tell about the failure to secondary. If so should run no monitor-interface  if name command to dis load devices and network by foolish  tests?

View 5 Replies View Related

Cisco Firewall :: Enabling RIP On PIX 535 / Error / OSPF / RIP Cannot Be Enabled On Failover Interface

Jun 29, 2012

I am getting this error on my PIX 535 with 8.0.4 code. The error is Error : OSPF/RIP cannot be enabled on failover interface, I am getting this error while trying to enable RIP on the firewall. The context is single mode and failover is enabled. When I am disabling the failover the Firewall is accepting the RIP configurations.

View 2 Replies View Related

Cisco Firewall :: ASA 5520 - Interface Reconfiguration In Active / Passive Failover

Dec 20, 2011

Currently l have two ASA 5520's in a active/passive failover scenario.  Currently the interfaces for the inside and outside are fixed at 100/FULL.I want to repatch them into GigE ports setup as Auto Negotiate.Is there anyway of keeping the connections through the firewall active in this type of scenrio or will l have downtime disconnecting and repatching?  or could l possibly disable failover and reconfigure each ?

View 6 Replies View Related

Cisco Firewall :: ASA 5510 - Unknown 105008 And 105009 Logs On Non-failover Interface

Nov 26, 2012

I have a pair of ASA5510s in a failover configuration where I see these 2 logs repeated every 15 seconds. 
105008 1          Nov 27 2012          10:39:27        (Primary) Testing Interface management
105009 1          Nov 27 2012          10:39:28        (Primary) Testing on interface management Passed
I have read other threads where these are accompanied by "105005, Lost Failover communications with mate on interface".  But I'm only getting these 2.  The other thing that is confusing is that the "management" interface is not the failover interface.  So why do I see 105008/9 logs about it?
Output of "sh fail":
5510a# sh fail
Failover On
Failover unit Primary


View 6 Replies View Related

Cisco Firewall :: 5540 ASA Interface Input Error On Outside Interface

May 28, 2013

We are having Cisco ASA 5540 having Cisco Adaptive Security Appliance Software Version 8.0(5)23 at certain time of moment daily wer are facing latency and packetdrop wherin when I checked for ASA Interface which gives me " Input Errors" on outside interface ,so can any one tell me what are the causes to get input errors on cisco asa outisde interface.

View 2 Replies View Related

Cisco Firewall :: PIX 501 / Can Traffic Goes From Inside Interface To Outside Interface

Oct 9, 2011

I have Pix 501 firewall and I'm just configuring the device for "Email Server" to allowing POP/SMTP.
Inside Interface Address:
Outside Interface Address: ISP provided IP address
My question is can my traffic goes from inside interface to outside interface? (because the inside interface address not from 10.0/172./192.168 private address)Also I'm allowing internet from this email server ( so what my access list to be configured? and what my subnet mask shoud be there?
Pix(config)#access-list outbound permit tcp any eq 80
Pix(config)#access-list outbound permit udp any eq 53
Pix(config)#access-group outbound in interface inside

View 7 Replies View Related

Cisco Firewall :: ASA 5550 - Failover Is Not Replicating Configuration

Nov 11, 2012

I discover an issue with my CISCO ASA 5550 because I'm looking at the vlans that I have configured and some vlans on the Stand by device had not an IP address configured, checking the configuration of the failover

View 2 Replies View Related

Cisco Firewall :: ASA 5550 Lost SSH To Active On Failover?

Dec 19, 2010

I am having a curious problem with two Cisco ASA 5550. They are configured in Active/Standby failover and in routed mode.The problem is: I cannot connect via SSH to the ACTIVE unit, only to the STANDBY. If a switchover is forced the problem is still the same. because it happens both with the primary and the secondary unit.It is not a L2 or a transport problem, because I can ping or access both units via ASDM.

View 8 Replies View Related

Cisco Firewall :: ASA 5550 Failover License Requirements?

May 22, 2011

According to Cisco, one of the ASAs must have an Unrestricted License [URL]:
"On the PIX/ASA Security appliance platform, at least one of the units must have an unrestricted (UR) license.  The other unit can have a Failover Only Active-Active (FO_AA) license,  or another UR license. Units with a Restricted license cannot be used  for failover, and two units with FO_AA licenses cannot be used together  as a failover pair."I am unfamiliar with the different ASA licenses, so with my current license, I am unable to enable failover on my two ASAs. Here is a snippet of the "show version" output on one of my ASAs (they are the same as far as licenses go):

Licensed features for this platform:Maximum Physical Interfaces : UnlimitedMaximum VLANs : 250Inside Hosts : UnlimitedFailover : Active/ActiveVPN-DES : EnabledVPN-3DES-AES : EnabledSecurity Contexts : 5GTP/GPRS : DisabledSSL VPN Peers : 10Total VPN Peers : 5000Shared License : DisabledAnyConnect for Mobile : DisabledAnyConnect for Cisco VPN Phone : DisabledAnyConnect Essentials : DisabledAdvanced Endpoint Assessment : DisabledUC Phone Proxy Sessions : 2Total UC Proxy Sessions : 2Botnet Traffic Filter : Disabled
This platform has an ASA 5550 VPN Premium license.

View 5 Replies View Related

Cisco Firewall :: ASA 5550 Failover - Do Firewalls Have To Be At Same Site

Jun 8, 2011

I am trying think of a better way to provide redundancy on some internally protected networks.  We maintain our own WAN/backbone between our primary site and backup site.  Is it possible to have two Cisco ASA 5550s in setup for failover at completely different sites as long the networks connected are available?

View 3 Replies View Related

Cisco Firewall :: Configuring NAT Port Forwarding Failover On ASA 5550

Mar 26, 2011

I've two Cisco ASA 5550 firewall. I'm don't have much knowlege on configuring this kind of firewall. I need configuring these firewall for simple NAT. I have 3 public IP address. I would like to allow server's inside of the firewall to be able to connect to internet using private address. A basic NAT. Also need to configure some port forwarding. We've bought two firewall for the Active/Active failover support. How can i configure this through ASDM? My ASDM version is 5.2.

View 1 Replies View Related

Cisco Firewall :: Upgrade ASA 5550 Failover Pair From 8.2 To 8.4 Without Zero-downtime

Jun 28, 2011

Since the "zero-downtime upgrade" is not supported, I would like to validate the process I put together for upgrading a failover pair of asa5550 with the characteristics below. Specifically I am concerned with the role of the standby during the upgrade. This is my setup:
.- single context mode
.- active/standby
.- current firmware asa821-k8.bin / asdm-621.bin
.- role: firewall and VPN concentrator for segmented server farm network. Dynamic/static/exemption NAT heavily used.
My target is asa842-k8.bin / asdm-645.bin and I am doing a two step upgrade (8.2(1) -> 8.3(1) -> 8.4(2)) to avoid the "unidirectional" attribute and CSCtf89372 bug issues. This is a short version of what I have in mind:
.- Verify stability of failover pair and make adequate backups before beginning.
.- plug into the console of active, ssh into active and standby.
.- vpn/act(config)# no failover            ( disable failover from active )


After reboot, point to 8.4(2) and reload again.  Same concern regarding the standby unit.
I understand there might be configuration tweaks needed to the NAT configuration. After second reboot test connectivity and if successful, on active "failover", "write standby" and "failover reload-standby". Otherwise "downgrade" and back to the drawing board.

View 6 Replies View Related

Cisco :: ASA 5505 Failover Interface?

May 16, 2011

I need to configure one interface in failover because the client has 2 ISP.[CODE]

View 2 Replies View Related

2911 ISR - Setup New WAN Interface And Failover?

Oct 30, 2012

have been tasked with completing a Cisco config update on an ISR.Client is running a Cisco 2911 running IOS version is 15.0(1)M6.They have added a new WAN interface to GigabitEthernet0/2 and are looking to setup a basic failover configuration to augment their current 0/0 Fiber connection.

View 7 Replies View Related

Cisco WAN :: 1841 Router - HWIC Interface Card - Cannot See Interface In Configuration File

May 9, 2012

i have a 1841 cisco router and i recently purchased a 1 port HWIC wan interface card. My problem is that I cannot see the interface in my config file. Is there something i am missing?

View 8 Replies View Related

Cisco Switching/Routing :: ASA 5505 Cannot Ping From Inside Interface To Outside Interface

May 1, 2012

I have a Cisco ASA 5505 and I have my internal and external interfaces configured but I currently cannot ping from the inside to an IP Address on the outside.  I had this setup and working and I have another set of equirement that I am replacing that is working with my service provider so I know it is a configuration issue.  When I ping for example I get:
Destination host unreachable
Do I need to add a static route from my inside interface to my outside interfaces?   

: Saved
ASA Version 8.2(5)
hostname pxasa


View 2 Replies View Related

Cisco WAN :: Set Up WAN Interface On Fast Ethernet Interface Of 877 Adsl Router

Apr 9, 2011

Is it possible to set up a WAN interface on a FastEthernet interface of a Cisco 877 Adsl Router ?Due to my ISP, i've to use an external VDSL modem and must connect it to my cisco 877 router (and leave it's adsl interface unused).But i don't know how to set up a wan port, other than the adsl interface itself (dialer0), on my cisco.

View 7 Replies View Related

Release Interface Loopback Pseudo - Interface 1 / System Do Not Find File

Oct 31, 2011

I share a modem and router with my building, and connect to the internet using an ethernet cable which plus right into the wall in my apartment. When I hover over the network/internet icon it tells me that I have a local connection only and can't get online. No changes were made to my computer between it working and not working - I have not installed any new software and the modem+router have not been changed.

When I try ipconfig/release is says it can't perform the operation while the media is disconnected. It also tells me that "an error occurred while releasing interface Loopback Pseudo-Interface 1: The system cannot find the fie specified".


View 1 Replies View Related

Cisco WAN :: 1T3 / E3 / 2951 - No Interface Corresponding To Module When Show IP Interface Brief

Feb 13, 2012

I have a 1t3/e3 card in a new 2951. When I statred the router, I found no interface corresponding to this module when do "show ip interface brief"

View 3 Replies View Related

Cisco WAN :: 2900 - Bridge From WIC Interface To Ethernet Interface

Apr 22, 2012

Needing to bridge from my wic interface to an ethernet interface on a 2900 series router so that I can pass through the ip address given to the WIC, to my ASA so that I don't have to give my ASA a private range address. (Just like a service provider might do when bringing a T1 with managed router in to my prem)

View 1 Replies View Related

Cisco WAN :: 877 - Virtual Interface Goes Down But Not Physical Interface

Apr 5, 2011

I have five 877 routers connected to ADSL circuits provided by Vodafone. Each has a VPN tunnel back to a PIX.
Occasionally one of the sites will lose it's connection to the PIX.
When we check the log, we find entries like these:-

Apr  5 01:31:54.085 UTC: %LINEPROTO-5-UPDOWN: Line protocol on Interface Virtual-Access2, changed state to downApr  5 01:33:19.344 UTC: %CRYPTO-

As you can see, the physical interface (ATM0) is not being reported as changing state to down, neither is the Dialer interface.
When the router is in this state we have to SSL to the public IP address of it and manually restart the ISAKMP SA.
When the router sees the ATM interface go down and subsequently come back up, the VPN connection to the PIX also recovers.
So - in a long winded way I think I'm asking....why does the Virtual interface go down and is there anything I can do to stop it happening?

View 3 Replies View Related

Copyrights 2005-15, All rights reserved