Cisco ASA Track Backup Route

interface Ethernet0
nameif outside
security-level 0
ip address 10.200.159.2 255.255.255.248
!
interface Ethernet1
nameif backup

!— The interface attached to the Secondary ISP.
!— “backup” was chosen here, but any name can be assigned.

security-level 0
ip address 10.250.250.2 255.255.255.248
!

interface Ethernet2
nameif inside
security-level 100
ip address 172.16.1.163 255.255.255.0
!
!

global (outside) 1 interface
global (backup) 1 interface

nat (inside) 1 172.16.1.0 255.255.255.0

!— NAT Configuration for Outside and Backup


route outside 0.0.0.0 0.0.0.0 10.200.159.1 1 track 1


!— Enter this command in order to track a static route.
!— This is the static route to be installed in the routing
!— table while the tracked object is reachable.  The value after
!— the keyword “track” is a tracking ID you specify.


route backup 0.0.0.0 0.0.0.0 10.250.250.1 254


!— Define the backup route to use when the tracked object is unavailable.
!— The administrative distance of the backup route must be greater than
!— the administrative distance of the tracked route.
!— If the primary gateway is unreachable, that route is removed
!— and the backup route is installed in the routing table
!— instead of the tracked route.

!
!

sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10

!— Configure a new monitoring process with the ID 123.  Specify the
!— monitoring protocol and the target network object whose availability the tracking
!— process monitors.  Specify the number of packets to be sent with each poll.
!— Specify the rate at which the monitor process repeats (in seconds).

sla monitor schedule 123 life forever start-time now

!— Schedule the monitoring process.  In this case the lifetime
!— of the process is specified to be forever.  The process is scheduled to begin
!— at the time this command is entered.  As configured, this command allows the
!— monitoring configuration specified above to determine how often the testing
!— occurs.  However, you can schedule this monitoring process to begin in the
!— future and to only occur at specified times.

!
track 1 rtr 123 reachability

!— Associate a tracked static route with the SLA monitoring process.
!— The track ID corresponds to the track ID given to the static route to monitor:
!— route outside 0.0.0.0 0.0.0.0 10.0.0.2 1 track 1
!— “rtr” = Response Time Reporter entry.  123 is the ID of the SLA process
!— defined above.

!
!

VERIFY

Displays the SLA commands in the configuration
:

show running-config sla monitor

sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10
sla monitor schedule 123 life forever start-time now

Displays the current configuration settings of the operation :

show sla monitor configuration

pix# show sla monitor configuration 123
IP SLA Monitor, Infrastructure Engine-II.
Entry number: 123
Owner:
Tag:
Type of operation to perform: echo
Target address: 10.0.0.1
Interface: outside
Number of packets: 3
Request size (ARR data portion): 28
Operation timeout (milliseconds): 5000
Type Of Service parameters: 0x0
Verify data: No
Operation frequency (seconds): 10
Next Scheduled Start Time: Start Time already passed
Group Scheduled : FALSE
Life (seconds): Forever
Entry Ageout (seconds): never
Recurring (Starting Everyday): FALSE
Status of entry (SNMP RowStatus): Active
Enhanced History:


Displays the operational statistics of the SLA operation
:

show sla monitor operational-state

Before the primary ISP fails, this is the operational state:

show sla monitor operational-state 123
Entry number: 123
Modification time: 13:59:37.824 UTC Thu Oct 12 2006
Number of Octets Used by this Entry: 1480
Number of operations attempted: 367
Number of operations skipped: 0
Current seconds left in Life: Forever
Operational state of entry: Active
Last time this entry was reset: Never
Connection loss occurred: FALSE
Timeout occurred: FALSE
Over thresholds occurred: FALSE
Latest RTT (milliseconds): 1
Latest operation start time: 15:00:37.825 UTC Thu Oct 12 2006
Latest operation return code: OK
RTT Values:
RTTAvg: 1       RTTMin: 1       RTTMax: 1
NumOfRTT: 3     RTTSum: 3       RTTSum2: 3

After the primary ISP fails (and the ICMP echos time out), this is the operational state:

show sla monitor operational-state

Entry number: 123
Modification time: 13:59:37.825 UTC Thu Oct 12 2006
Number of Octets Used by this Entry: 1480
Number of operations attempted: 385
Number of operations skipped: 0
Current seconds left in Life: Forever
Operational state of entry: Active
Last time this entry was reset: Never
Connection loss occurred: FALSE
Timeout occurred: TRUE
Over thresholds occurred: FALSE
Latest RTT (milliseconds): NoConnection/Busy/Timeout
Latest operation start time: 15:03:27.825 UTC Thu Oct 12 2006
Latest operation return code: Timeout
RTT Values:
RTTAvg: 0       RTTMin: 0       RTTMax: 0
NumOfRTT: 0     RTTSum: 0       RTTSum2: 0

Confirm the Backup Route is Installed (CLI Method)

Use the show route command to determine when the backup route is installed.
Before the primary ISP fails, this is the routing table:

show route

Gateway of last resort is 10.200.159.1 to network 0.0.0.0

S    64.101.0.0 255.255.0.0 [1/0] via 172.22.1.1, inside
C    172.22.1.0 255.255.255.0 is directly connected, inside
C    10.250.250.0 255.255.255.248 is directly connected, backup
C    10.200.159.0 255.255.255.248 is directly connected, outside
S*   0.0.0.0 0.0.0.0 [1/0] via 10.200.159.1, outside


After the primary ISP fails, the static route is removed,
and the backup route is installed, this is the routing table:

show route

Gateway of last resort is 10.250.250.1 to network 0.0.0.0

S    64.101.0.0 255.255.0.0 [1/0] via 172.22.1.1, inside
C    172.22.1.0 255.255.255.0 is directly connected, inside
C    10.250.250.0 255.255.255.248 is directly connected, backup
C    10.200.159.0 255.255.255.248 is directly connected, outside
S*   0.0.0.0 0.0.0.0 [254/0] via 10.250.250.1, backup

Troubleshoot

Debug Commands

Displays progress of the echo operation :

debug sla monitor
trace

The tracked object (primary ISP gateway) is up, and ICMP echos succeed.
The tracked object (primary ISP gateway) is down, and ICMP echos fail.

Displays errors that the SLA monitor process encounters :

debug sla monitor error

The tracked object (primary ISP gateway) is up, and ICMP succeeds.
The tracked object (primary ISP gateway) is down, and the tracked route is removed.

!— 10.0.0.1 is unreachable, so the route to the Primary ISP is removed.

Tracked Route is Removed Unnecessarily

If the tracked route is removed unnecessarily, ensure that your monitoring target
is always available to receive echo requests. In addition, ensure that the state
of your monitoring target (that is, whether or not the target is reachable) is
closely tied to the state of the primary ISP connection.


If you choose a monitoring target that is farther away than the ISP gateway,
another link along that route may fail or another device may interfere.
This configuration may cause the SLA monitor to conclude that the connection
to the primary ISP has failed and cause the security appliance to unnecessarily
fail over to the secondary ISP link.

For example, if you choose a branch office router as your monitoring target,
the ISP connection to your branch office could fail, as well as any other link
along the way. Once the ICMP echos that are sent by the monitoring operation fail,
the primary tracked route is removed, even though the primary ISP link is still active.

In this example, the primary ISP gateway that is used as the monitoring target is
managed by the ISP and is located on the other side of the ISP link.
This configuration ensures that if the ICMP echos that are sent by the monitoring
operation fail, the ISP link is almost surely down.

SLA Monitoring on ASA

Problem:

SLA monitoring does not work after the ASA is upgrade to version 8.0.

Solution:

The problem is possibly be due to the IP Reverse-Path command configured in the
OUTSIDE interface.
Remove the command in ASA and try to check the SLA Monitoring.