Guest

Preview Tool

Cisco Bug: CSCun08157 - Slow DAP ACL failover replication

Last Modified

Apr 20, 2020

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

8.4(5.7) 9.1(4)

Description (partial)

Symptom:
Large size DACLs (20K+ lines) can take several minutes to replicate to failover standby unit.  AAA process is locked for duration of replication time, thus disallowing additional user logins until replication is complete.

Conditions:
ASA running as member of failover pair.  DAP in place to build DACLs.  Large-size DACLs (tens of thousands of lines) result from policies.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.