NetworkDOC
MIS
Just recently bought a 515E Failover edition. Put it in place and all works fine, for a while. I can do the show failover and it shows up as Primary (520) standby, Secondary (active). Then the roles flip around a while, from active/active, active/active failed, active/standby failed etc. The users complain of dropped connections. For example when it flips the failover state around and I have a Citrix connection up, it drops it then reconnects, then drops repeatedly.
This is a fairly new failover pix (3-4 months old). We moved the company during this time and the secondary pix was off. If it's off all works great. Once it comes up it will begin to act ugly. Yesterday I did a faliover reset and this seemed to clear things up for a while but then it started it again.
Any ideas? I included the states at different intervals. These were captured over a few minutes. Also the ips have been change to protect the innocent....
ON the PRimary PIX
sh failover
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:00:59 UTC Wed May 10 2006
This host: Primary - Standby (the 520 pix)
Active time: 720 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Other host: Secondary - Active (the 515 Pix)
Active time: 75 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.232): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
Failover config as seen on the primary pix
failover
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
no failover ip address DMZ
After setting it to active failover from "primary"
Failover On
Cable status: Other side powered off
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:29:01 UTC Wed May 10 2006
This host: Primary - Active
Active time: 960 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Other host: Secondary - Standby
Active time: 510 (sec)
Interface outside (0.0.0.0): Unknown (Waiting)
Interface inside (0.0.0.0): Unknown (Waiting)
Interface DMZ (0.0.0.0): Unknown (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
After typing in at the "secondary" no failover active
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 12:00:54 UTC Tue May 9 2006
This host: Secondary - Active
Active time: 450 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Interface intf3 (0.0.0.0): Link Down (Shutdown)
Interface intf4 (0.0.0.0): Link Down (Shutdown)
Interface intf5 (0.0.0.0): Link Down (Shutdown)
Other host: Primary - Standby (Failed)
Active time: 1185 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Interface intf3 (0.0.0.0): Unknown (Shutdown)
Interface intf4 (0.0.0.0): Unknown (Shutdown)
Interface intf5 (0.0.0.0): Unknown (Shutdown)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
on the "primary" at the console:
sh failover
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:36:14 UTC Wed May 10 2006
This host: Primary - Active
Active time: 1260 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Other host: Secondary - Active
Active time: 480 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
Then it changed to:
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:36:14 UTC Wed May 10 2006
This host: Primary - Active
Active time: 1365 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Other host: Secondary - Standby
Active time: 555 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
This is a fairly new failover pix (3-4 months old). We moved the company during this time and the secondary pix was off. If it's off all works great. Once it comes up it will begin to act ugly. Yesterday I did a faliover reset and this seemed to clear things up for a while but then it started it again.
Any ideas? I included the states at different intervals. These were captured over a few minutes. Also the ips have been change to protect the innocent....
ON the PRimary PIX
sh failover
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:00:59 UTC Wed May 10 2006
This host: Primary - Standby (the 520 pix)
Active time: 720 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Other host: Secondary - Active (the 515 Pix)
Active time: 75 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.232): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
Failover config as seen on the primary pix
failover
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
no failover ip address DMZ
After setting it to active failover from "primary"
Failover On
Cable status: Other side powered off
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:29:01 UTC Wed May 10 2006
This host: Primary - Active
Active time: 960 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Other host: Secondary - Standby
Active time: 510 (sec)
Interface outside (0.0.0.0): Unknown (Waiting)
Interface inside (0.0.0.0): Unknown (Waiting)
Interface DMZ (0.0.0.0): Unknown (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
After typing in at the "secondary" no failover active
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 12:00:54 UTC Tue May 9 2006
This host: Secondary - Active
Active time: 450 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Interface intf3 (0.0.0.0): Link Down (Shutdown)
Interface intf4 (0.0.0.0): Link Down (Shutdown)
Interface intf5 (0.0.0.0): Link Down (Shutdown)
Other host: Primary - Standby (Failed)
Active time: 1185 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Interface intf3 (0.0.0.0): Unknown (Shutdown)
Interface intf4 (0.0.0.0): Unknown (Shutdown)
Interface intf5 (0.0.0.0): Unknown (Shutdown)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
on the "primary" at the console:
sh failover
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:36:14 UTC Wed May 10 2006
This host: Primary - Active
Active time: 1260 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Other host: Secondary - Active
Active time: 480 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.
Then it changed to:
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 01:36:14 UTC Wed May 10 2006
This host: Primary - Active
Active time: 1365 (sec)
Interface outside (16.2.166.2): Normal (Waiting)
Interface inside (10.0.0.1): Normal (Waiting)
Interface DMZ (10.10.1.1): Normal (Waiting)
Other host: Secondary - Standby
Active time: 555 (sec)
Interface outside (0.0.0.0): Normal (Waiting)
Interface inside (0.0.0.0): Normal (Waiting)
Interface DMZ (0.0.0.0): Normal (Waiting)
Stateful Failover Logical Update Statistics
Link : Unconfigured.