<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malcom Gladwell would say in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/3394781#M1029555</link>
    <description>&lt;P&gt;Hi Malcom,&lt;/P&gt;
&lt;P&gt;If your sfr is already working in ''monitor mode'' and now you want to go with inline mode then apart from just typing ''sfr fail-open'' under class map&lt;/P&gt;
&lt;P&gt;You need go through logs that generated by firepower when it was in monitor mode bcz there is an option it will tell ''what if i would be in INLINE mode''&amp;nbsp;&lt;BR /&gt;you may need to spend time to see those logs bcz based on your policy configuration it may block some&amp;nbsp;legitimate traffic of your network or may allow some malicious traffic to/from your network.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jun 2018 07:31:14 GMT</pubDate>
    <dc:creator>salman abid</dc:creator>
    <dc:date>2018-06-06T07:31:14Z</dc:date>
    <item>
      <title>sfr fail-open: will it failover over to secondary if SFR fails on primary?</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955639#M1029538</link>
      <description>&lt;P&gt;Pair of 5515-x with SFR , in Active/Standby&amp;nbsp;failover.&lt;/P&gt;
&lt;P&gt;Policy-map is configured for: &amp;nbsp;&lt;STRONG&gt;sfr fail-open&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If SFR fails on primary/active device, is:&lt;/P&gt;
&lt;P&gt;1. primary device stays active since it's configured for sfr fail-open?&lt;/P&gt;
&lt;P&gt;2. failover occurs and secondary becomes active since primary is no longer healthy?&lt;/P&gt;
&lt;P&gt;I think the answer is 2, but I would like a confirmation.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Cath.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955639#M1029538</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2019-03-12T13:06:52Z</dc:date>
    </item>
    <item>
      <title>Cath,</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955640#M1029540</link>
      <description>&lt;P&gt;Cath,&lt;/P&gt;
&lt;P&gt;Service module health is by default checked as part of the failover criteria in an ASA HA pair (or cluster). If the service module fails, that will trigger a failover event (assuming the Standby unit is in ready state).&lt;/P&gt;
&lt;P&gt;As of ASA software 9.5(1) there is an option to change this default behavior with the command "&lt;STRONG&gt;no &amp;nbsp;health-check monitor-interface service-module&lt;/STRONG&gt;".&lt;/P&gt;</description>
      <pubDate>Sat, 27 Aug 2016 19:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955640#M1029540</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-08-27T19:27:20Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin.  That is what</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955641#M1029544</link>
      <description>&lt;P&gt;Thanks Marvin. &amp;nbsp;That is what I thought. &amp;nbsp;I was aware also of the new features in 9.5 to not have the module considered for failover.&lt;/P&gt;
&lt;P&gt;Marvin, your replies are always clear, concise and precise. &amp;nbsp;Your continuous contribution to the support forum is greatly appreciated.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Cath.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Aug 2016 21:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955641#M1029544</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2016-08-27T21:19:12Z</dc:date>
    </item>
    <item>
      <title>You're welcome Cath.</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955642#M1029546</link>
      <description>&lt;P&gt;You're welcome Cath.&lt;/P&gt;
&lt;P&gt;Thank you for the kind words of encouragement. I've been at it here in the Cisco community forums for just over 15 years (CSC's predecessor Netpro started in 2000 the year before I joined); so I've pretty much got it figured out.&lt;/P&gt;
&lt;P&gt;I read somewhere that an expert is somebody who's already made most of the mistakes (at least once). I might have a few more left to make; but I've had my fair share. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Aug 2016 21:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955642#M1029546</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-08-27T21:49:37Z</dc:date>
    </item>
    <item>
      <title>Malcom Gladwell would say</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955643#M1029549</link>
      <description>Malcom Gladwell would say that an expert is someone who has put 10,000 hours practicing their skills.  I'm sure you are well over that time threshold.
Thanks again for your contribution.
Cath.</description>
      <pubDate>Sat, 27 Aug 2016 21:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/2955643#M1029549</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2016-08-27T21:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Malcom Gladwell would say</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/3383886#M1029552</link>
      <description>&lt;P&gt;I have my Any Connect VPN and Site to Site VPN Traffic redirected to SFR module while configuring almost similar to below rule. Difference is in my box I have configured the traffic here what I mentioned as XXXX.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# access-list sfr_redirect extended permit ip XXXX XXXX&lt;BR /&gt;ciscoasa(config)# class-map sfr&lt;BR /&gt;ciscoasa(config-cmap)# match access-list sfr_redirect&lt;BR /&gt;ciscoasa(config-pmap-c)# sfr fail-open monitor-only&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I need to configure this as an Inline Mode to start Inspecting the traffic. What are the steps I need to do to accomplish this other than configuring below command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ciscoasa(config-pmap-c)# sfr fail-open&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 03:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/3383886#M1029552</guid>
      <dc:creator>subrun.jamil</dc:creator>
      <dc:date>2018-05-16T03:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Malcom Gladwell would say</title>
      <link>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/3394781#M1029555</link>
      <description>&lt;P&gt;Hi Malcom,&lt;/P&gt;
&lt;P&gt;If your sfr is already working in ''monitor mode'' and now you want to go with inline mode then apart from just typing ''sfr fail-open'' under class map&lt;/P&gt;
&lt;P&gt;You need go through logs that generated by firepower when it was in monitor mode bcz there is an option it will tell ''what if i would be in INLINE mode''&amp;nbsp;&lt;BR /&gt;you may need to spend time to see those logs bcz based on your policy configuration it may block some&amp;nbsp;legitimate traffic of your network or may allow some malicious traffic to/from your network.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 07:31:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-fail-open-will-it-failover-over-to-secondary-if-sfr-fails-on/m-p/3394781#M1029555</guid>
      <dc:creator>salman abid</dc:creator>
      <dc:date>2018-06-06T07:31:14Z</dc:date>
    </item>
  </channel>
</rss>

