<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM command required or not? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774383#M1006592</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failover will still work even without monitored interfaces but it will not be very efficient ie. only if the whole unit goes down will failover happen. The FWSM uses the failover link to monitor the other FWSM. If the standby loses connectivity with the active then it assumes the active role. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem with this is that if you lose some of your firewall interfaces eg the outside interface and you are not monitoring it then the FWSM will not failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking you should monitor the important interfaces. If you use a shared vlan, for exmaple on the outside interfaces, you only need to monitor the outside interface in one of your contexts ( if you are using contexts that is ). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can set a threshold of interfaces that are monitored that must fail before failover happens. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a link to the FWSM 3.1 failover confgiuration section. Have a look at the failover triggers to explain all of this in more detail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080602f98.html#wp1046889" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080602f98.html#wp1046889&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Apr 2007 16:34:48 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-04-20T16:34:48Z</dc:date>
    <item>
      <title>FWSM command required or not?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774382#M1006587</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use two FWSM's in active/standby failover configuration in two different chassis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A 'show failover' command output shows that interfaces are not monitored for failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone told me this monitoring is not an option, but SHOULD be turned on to let failover function at all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure this is not true and failover also works fine in case of a failing fwsm, but cannot find it in documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone help me out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failover On &lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: fover-int Vlan 405 (up)&lt;/P&gt;&lt;P&gt;Unit Poll frequency 15 seconds, holdtime 45 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 15 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 50%&lt;/P&gt;&lt;P&gt;Monitored Interfaces 0 of 250 maximum&lt;/P&gt;&lt;P&gt;Config sync: active&lt;/P&gt;&lt;P&gt;Version: Ours 3.1(3), Mate 3.1(3)&lt;/P&gt;&lt;P&gt;Last Failover at: 09:51:03 MET Jan 3 2007&lt;/P&gt;&lt;P&gt;        This host: Primary - Active &lt;/P&gt;&lt;P&gt;                Active time: 9260490 (sec)&lt;/P&gt;&lt;P&gt;                Interface outside (10.2.3.4): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                Interface inside (10.2.4.4): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;                Interface homewurks (10.2.5.4): Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Etc..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774382#M1006587</guid>
      <dc:creator>Erik Molenaar</dc:creator>
      <dc:date>2019-03-11T10:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM command required or not?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774383#M1006592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failover will still work even without monitored interfaces but it will not be very efficient ie. only if the whole unit goes down will failover happen. The FWSM uses the failover link to monitor the other FWSM. If the standby loses connectivity with the active then it assumes the active role. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem with this is that if you lose some of your firewall interfaces eg the outside interface and you are not monitoring it then the FWSM will not failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking you should monitor the important interfaces. If you use a shared vlan, for exmaple on the outside interfaces, you only need to monitor the outside interface in one of your contexts ( if you are using contexts that is ). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can set a threshold of interfaces that are monitored that must fail before failover happens. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a link to the FWSM 3.1 failover confgiuration section. Have a look at the failover triggers to explain all of this in more detail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080602f98.html#wp1046889" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080602f98.html#wp1046889&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2007 16:34:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774383#M1006592</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-20T16:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM command required or not?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774384#M1006599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon for your explanantion!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2007 07:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-command-required-or-not/m-p/774384#M1006599</guid>
      <dc:creator>Erik Molenaar</dc:creator>
      <dc:date>2007-04-23T07:11:23Z</dc:date>
    </item>
  </channel>
</rss>

