<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD Failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170840#M1075004</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest to use the switch in stack for MPLS and in LAN side you can use both the switches connected via Trunk.&lt;/P&gt;&lt;P&gt;In this condition if case active firewall failover also you do not need to do switch side failover.&lt;/P&gt;&lt;P&gt;IN HA at a time only one firewall will be processing traffic and other will be in standby mode hence even it secondary firewall port is up also it does not create any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;AKK&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2020 08:25:38 GMT</pubDate>
    <dc:creator>AKK</dc:creator>
    <dc:date>2020-10-21T08:25:38Z</dc:date>
    <item>
      <title>FTD Failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170676#M1074995</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the following setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MPLS switch--Cisco FTD--Switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco FTD is configured in high availability mode. The primary FTD is connected to the primary MPLS switch and the standby FTD to the standby MPLS switch. Recently, the ftd failover happened and the standby ftd became active, however the MPLS switch did not failover as the link connecting the switch to the ftd was still up. Is there anyway to make the link down when the ftd is in standby mode?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 05:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170676#M1074995</guid>
      <dc:creator>dijeshkeloth</dc:creator>
      <dc:date>2020-10-21T05:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170694#M1074996</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The best option for full HA is to connect your switches using a trunk cable&lt;BR /&gt;and get full mesh. This means that primary FTD can communicate to&lt;BR /&gt;primary/secondary MPLS and same for secondary FTD. You can also use&lt;BR /&gt;stackwise if supported by the switches. This is the best design.&lt;BR /&gt;&lt;BR /&gt;I don't recommend you to start using custom solutions to failover. Things&lt;BR /&gt;like EEM and tracking can be used as workaround but do it right to live&lt;BR /&gt;forever.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 21 Oct 2020 05:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170694#M1074996</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-10-21T05:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170796#M1075000</link>
      <description>&lt;P&gt;we do see that kind of environment, some places they want to extend Layer 2 using the different path in the network layer2 switch&lt;/P&gt;
&lt;P&gt;to meet the best do you have an alternative layer 2 paths for that? if not you need to use some kind of tracking, but Layer2 will be always up once side, others go down also. this is a bit tricky, as suggested you can use EEM script to keep monitor each side and shutdown or failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but it will have a small interruption of traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 07:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170796#M1075000</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-10-21T07:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170840#M1075004</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest to use the switch in stack for MPLS and in LAN side you can use both the switches connected via Trunk.&lt;/P&gt;&lt;P&gt;In this condition if case active firewall failover also you do not need to do switch side failover.&lt;/P&gt;&lt;P&gt;IN HA at a time only one firewall will be processing traffic and other will be in standby mode hence even it secondary firewall port is up also it does not create any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;AKK&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 08:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4170840#M1075004</guid>
      <dc:creator>AKK</dc:creator>
      <dc:date>2020-10-21T08:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4172331#M1075076</link>
      <description>&lt;P&gt;Thanks All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please share a sample EEM script that i can use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 06:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4172331#M1075076</guid>
      <dc:creator>dijeshkeloth</dc:creator>
      <dc:date>2020-10-23T06:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4172409#M1075081</link>
      <description>&lt;P&gt;I don't think using EEM would be recommended tbh, I think best practice would be as already mentioned to connect MPLS and FTD devices to the same switch or switch stack. That way, when failover happens, the traffic will still flowing out of the active MPLS, regardless which one is going to be.&lt;/P&gt;&lt;P&gt;Or maybe if you are pointing to a floating IP address for MPLS routes with HSRP or VRRP, you can ask your ISP to condition HSRP or VRRP to failover the MPLS circuit if they can't reach a specific IP behind your primary FTD.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 08:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failover/m-p/4172409#M1075081</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-23T08:25:26Z</dc:date>
    </item>
  </channel>
</rss>

