ASA1(config)# nameif outside
ASA1(config)# ip address 150.10.0.13 255.255.255.0 standby 150.10.0.14
ASA1(config)# no shut
ASA1(config)# nameif inside
ASA1(config)# ip address 10.0.0.13 255.255.255.0 standby 10.0.0.14
ASA1(config)# no shut
ASA1(config)# exit
ASA1(config-router)# ver 2
ASA1(config-router)# network 10.0.0.0
ASA1(config-router)# no auto-summary
ASA1(config-router)# exit
ASA1(config-network-object)# subnet 0 0
ASA1(config-network-object)# nat (inside,outside) dynamic interface
ASA1(config-network-object)# exit!– permit icmp for testing
ASA1(config)# access-group OUT-IN in interface outside
ASA1(config)# failover lan interface FAILOVER-INT et0/3
ASA1(config)# failover link FAILOVER-INT e0/3
ASA1(config)# failover interface ip FAILOVER-INT 1.1.1.13 255.255.255.0 standby 1.1.1.14
ASA1(config)# failoverASA1(config)# monitor-interface outside
ASA1(config)# monitor-interface inside
ASA1(config)# failover polltime unit msec 200 holdtime msec 800
ASA1(config)# failover polltime interface msec 500 holdtime 5
ASA1(config)# failover interface-policy 1
ASA2(config-if)# no shut
ASA2(config-if)# exitASA2(config)# failover lan unit secondary
ASA2(config)# failover lan interface FAILOVER-INT e0/3
ASA2(config)# failover link FAILOVER-INT e0/3
Mate version 8.4(5) is not identical with ours 8.4(6)
************WARNING****WARNING****WARNING********************************
This host – Primary
Active None
Other host – Secondary
Standby Ready Comm Failure 14:33:36 UTC Sep 6 2013
Failover On
Failover unit Primary
Failover LAN Interface: FAILOVER-INT Ethernet0/3 (up)
Unit Poll frequency 200 milliseconds, holdtime 800 milliseconds
Interface Poll frequency 500 milliseconds, holdtime 5 seconds
Interface Policy 1
Monitored Interfaces 2 of 110 maximum
Version: Ours 8.4(5), Mate 8.4(6)
Last Failover at: 14:33:20 UTC Sep 6 2013
This host: Primary – Active
Active time: 1005 (sec)
slot 0: ASA5510 hw/sw rev (2.0/8.4(5)) status (Up Sys)
Interface outside (150.10.0.13): Normal (Monitored)
Interface inside (10.0.0.13): Normal (Monitored)
slot 1: empty
Other host: Secondary – Standby Ready
Active time: 0 (sec)
slot 0: ASA5510 hw/sw rev (2.0/8.4(6)) status (Up Sys)
Interface outside (150.10.0.14): Normal (Monitored)
Interface inside (10.0.0.14): Normal (Monitored)
slot 1: emptyStateful Failover Logical Update Statistics
Link : FAILOVER-INT Ethernet0/3 (up)
Stateful Obj xmit xerr rcv rerr
General 11 0 10 0
sys cmd 10 0 10 0
up time 0 0 0 0
RPC services 0 0 0 0
TCP conn 0 0 0 0
UDP conn 0 0 0 0
ARP tbl 0 0 0 0
Xlate_Timeout 0 0 0 0
IPv6 ND tbl 0 0 0 0
VPN IKEv1 SA 0 0 0 0
VPN IKEv1 P2 0 0 0 0
VPN IKEv2 SA 0 0 0 0
VPN IKEv2 P2 0 0 0 0
VPN CTCP upd 0 0 0 0
VPN SDI upd 0 0 0 0
VPN DHCP upd 0 0 0 0
SIP Session 0 0 0 0
Route Session 0 0 0 0
User-Identity 1 0 0 0
Logical Update Queue Information
Cur Max Total
Recv Q: 0 2 10
Xmit Q: 0 25 108
ASA1#
************WARNING****WARNING****WARNING********************************
Mate version 8.4(6) is not identical with ours 8.4(5)
************WARNING****WARNING****WARNING*****************************
router rip
network 136.1.0.0
version 2
no auto-summary
ASA1#
11 in use, 13 most used
TCP outside 150.10.0.2:23 inside 10.0.0.1:38081, idle 0:00:01, bytes 67, flags UIO
ASA1#
11 in use, 13 most used
TCP outside 150.10.0.2:23 inside 10.0.0.1:38081, idle 0:01:07, bytes 67, flags UIO
ASA1#
Switching to Standby
Failover On
Failover unit Secondary
Failover LAN Interface: FAILOVER Ethernet0/3 (up)
Unit Poll frequency 200 milliseconds, holdtime 800 milliseconds
Interface Poll frequency 500 milliseconds, holdtime 5 seconds
Interface Policy 1
Monitored Interfaces 2 of 110 maximum
Version: Ours 8.4(3), Mate 8.4(5)
Last Failover at: 16:10:44 UTC Sep 9 2013
This host: Secondary – Active
Active time: 117 (sec)
slot 0: ASA5510 hw/sw rev (2.0/8.4(3)) status (Up Sys)
Interface outside (150.10.0.13): Normal (Waiting)
Interface inside (10.0.0.13): Normal (Monitored)
slot 1: empty
Other host: Primary – Failed
Active time: 844 (sec)
slot 0: ASA5510 hw/sw rev (2.0/8.4(5)) status (Up Sys)
Interface outside (150.10.0.14): No Link (Waiting)
Interface inside (10.0.0.14): Normal (Monitored)
slot 1: emptyStateful Failover Logical Update Statistics
Link : FAILOVER Ethernet0/3 (up)
Stateful Obj xmit xerr rcv rerr
General 76 0 82 0
sys cmd 75 0 75 0
up time 0 0 0 0
RPC services 0 0 0 0
TCP conn 1 0 4 0
UDP conn 0 0 0 0
ARP tbl 0 0 2 0
Xlate_Timeout 0 0 0 0
IPv6 ND tbl 0 0 0 0
VPN IKEv1 SA 0 0 0 0
VPN IKEv1 P2 0 0 0 0
VPN IKEv2 SA 0 0 0 0
VPN IKEv2 P2 0 0 0 0
VPN CTCP upd 0 0 0 0
VPN SDI upd 0 0 0 0
VPN DHCP upd 0 0 0 0
SIP Session 0 0 0 0
Route Session 0 0 0 0
User-Identity 0 0 1 0
Logical Update Queue Information
Cur Max Total
Recv Q: 0 5 648
Xmit Q: 0 1 188
ASA1#
In failover, one firewall unit is designated as primary and the other as secondary. Initially, the primary unit is active and the secondary is standby. Only one unit is active and forwards traffic at any given time, while the other remains in standby mode. When the active unit fails, the standby assumes the role of the active unit by taking its IP/MAC addresses. The unit still remains known as the “secondary” unit, but it operates in an “active” mode. Failover is available in both transparent firewall and routed firewall modes.
failover ! Configure interface monitoring and failover policy
monitor-interface inside! Setup unit & interface polling using minimum values available
failover polltime unit msec 200 holdtime msec 800
failover polltime interface msec 500 holdtime 5
failover interface-policy 1