Loading...
Loading...
FTD devices in HA can go to Active/Active state, if failover ipsec encryption is enabled. 'Show blocks' output will show that the 1550 block is depleted. ------------------ show blocks ------------------ SIZE MAX LOW CNT 0 8700 8570 8700 4 1700 1698 1699 80 9000 8868 9000 256 38348 6083 38342 1550 70000 0 69998 <<<<<<<<<< 2048 8100 7989 8100 2560 8192 8190 8192 4096 100 98 100 8192 100 99 100 9344 25000 24998 25000 16384 320 320 320 65536 16 16 16 From the syslogs we are seeing the following messages: %ASA-3-105010: (Primary) Failover message block alloc failed block depletion of process async_lock_q
FTD/ASA in HA pair with failover ipsec encryption enabled Versions of 6.x, Versions of 7.2.7, 7.4, and lower 7.0.
> Disable failover ipsec encryption > Encrypt HA data on seperate device over standard VPN tunnel
Customers often need this feature due to distributed physical locations of devices, with HA data passing across external networks. This effectively forms an on-box VPN tunnel between HA FTDs
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.