<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable interface status alerts on the passive FTD in a failover p in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693644#M1093654</link>
    <description>&lt;P&gt;What version are you running on those devices? the behaviour might have changed comparing to the 6.x release. I think the reason why you see that option greyed out is because you are trying to edit the health policy that is applied to both firewalls without excluding any device from that policy. Did you select the passive device and clicked on "Exclude Selected Devices" and you still see that option greyed out?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 10:17:45 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2022-09-26T10:17:45Z</dc:date>
    <item>
      <title>Disable interface status alerts on the passive FTD in a failover pair</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4691812#M1093563</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have two FTD 4112 in a failover pair and we receive lots of interface alerts from the passive device. This is of cause expected, but I want to disable those alerts, but only on the passive unit. Is this possible? I created a separate health policy for the secondary FTD, but it seems like I cannot assign a different health policy’s for a device in a failover pair.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 07:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4691812#M1093563</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-22T07:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4691839#M1093566</link>
      <description>&lt;P&gt;Yes that can be done from the health policy, I can't remember the exact option that should be used and I don't have access to an FTP build at the moment, sorry. However, one downside of this is that when a failover happen where now the active device is the secondary, and say something happens to that interface that you disabled the alerts to, you won't be aware of that failure/issue. So my recommendation would be to keep those alerts on to allow you visibility in case the interface should fail if the secondary device should become active.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 09:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4691839#M1093566</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-22T09:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4691888#M1093569</link>
      <description>&lt;P&gt;Thanks. Yes, that is a downside that we risk loosing interface alerts if the secondary unit becomes active. However, we should then start getting interface alerts from the primary device instead and that should tell us that someting have happend with the primary device. Anyway, I can't figure out how to only select the secondary device and assign it to a different health policy than the primary device is using. I've attached a picture with the policy I want to assign to the secondary device, but if I select the secondary device, it will automatcly select the primary device as well. This is probably because it's a failover pair, but is there another way to have different health policys assigned to two devices in a failover pair?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Skärmklipp.JPG" style="width: 518px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163135i21C7EBB70A42C7EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Skärmklipp.JPG" alt="Skärmklipp.JPG" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 09:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4691888#M1093569</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-22T09:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692057#M1093573</link>
      <description>&lt;P&gt;I logged into one of my builds and here is how I had done that. I duplicated the health policy, turned off the "Interface Status" alerts, and then applied this new health policy to the secondary device only. When you click on the apply button (the first from left on the far right next to the policy name) it will allow you to select which device you want to apply the policy to, you don't have to select the HA pair, you can select the device individually.&lt;/P&gt;
&lt;P&gt;However as mentioned before, by doing this you will need to turn the "Interface Status" alerts back on if the secondary device should become the active. Because now that this specific policy with the "Interface Status" alerts are off is applied to that secondary device, when that device becomes the active the "Interface Status" alerts won't be generated. You would also need to turn the "Interface Status" alerts off on the new passive device (old primary).&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 11:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692057#M1093573</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-22T11:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692090#M1093577</link>
      <description>&lt;P&gt;That's exactly how I've done it. However, I cannot select a single device. If I select only the passive firewall, the active one will be automatically selected as well.&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:25:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692090#M1093577</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-22T12:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692099#M1093579</link>
      <description>&lt;P&gt;Mmm, honestly I can't remember if I had to break the failover HA temporarily to apply that change or not, but now that you said this it makes me feeling that I had to break the HA to do it.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692099#M1093579</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-22T12:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692100#M1093580</link>
      <description>&lt;P&gt;Reading the comments on this blog -&amp;nbsp;&lt;A title="Why is my Health status on my Cisco FMC always Critical?" href="https://www.lammle.com/post/health-policy-status-cisco-fmc-always-critical/" target="_self"&gt;https://www.lammle.com/post/health-policy-status-cisco-fmc-always-critical/&lt;/A&gt;&amp;nbsp; a suggested workaround is to use the blacklist/exclude option instead. If I use that, I can choose to select only the passive device in the H/A pair but for some reason, the interface status option is not selectable. (See picture)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Skärmklipp.JPG" style="width: 440px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163137i1E9BF075855B7FBC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Skärmklipp.JPG" alt="Skärmklipp.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692100#M1093580</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-22T12:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692122#M1093585</link>
      <description>&lt;P&gt;I must have done that through the exclude list then :), tomorrow I'll try to log into one of my customers build where I know I have applied that alert suppression, and if it is done differently than using the excluding list I'll post back here.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 13:18:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692122#M1093585</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-22T13:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692124#M1093586</link>
      <description>&lt;P&gt;Chess, actually I had done that through the blacklist/exclude feature, in fact, I also created a post on my blog more than two years ago to show how to do it :). Sorry I couldn't remember this before, I must be getting older :). Here is the post link, please look at the "Blacklist Interface Status alerts on FTDv-03 appliance" section where exactly shows you the steps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bluenetsec.com/fmc-health-monitor-blacklist/" target="_blank" rel="noopener"&gt;FMC Health Monitor Blacklist | Blue Network Security (bluenetsec.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 13:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4692124#M1093586</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-22T13:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693587#M1093653</link>
      <description>&lt;P&gt;I'm not able to exclude interface status alerts (that option is greyed out) Any idea why?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Skärmklipp.JPG" style="width: 330px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163345i0DBE1A2B90D18C85/image-size/large?v=v2&amp;amp;px=999" role="button" title="Skärmklipp.JPG" alt="Skärmklipp.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 08:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693587#M1093653</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-26T08:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693644#M1093654</link>
      <description>&lt;P&gt;What version are you running on those devices? the behaviour might have changed comparing to the 6.x release. I think the reason why you see that option greyed out is because you are trying to edit the health policy that is applied to both firewalls without excluding any device from that policy. Did you select the passive device and clicked on "Exclude Selected Devices" and you still see that option greyed out?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 10:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693644#M1093654</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-26T10:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693706#M1093662</link>
      <description>&lt;P&gt;It's version 7.0.1 on both the FMC and FTD. Both devices in the H/A pair are using the same health policy (It's not possible to use&amp;nbsp; separate ones). Here's what I tried:&amp;nbsp; I went to System-&amp;gt;Health-&amp;gt;Exclude and marked only the secondary/passive appliance and then I pushed the "exclude selected device" button. After that I can exclude most alert types, but not all. Interface status is one of the alerts I cannot choose to exclude.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 12:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693706#M1093662</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-26T12:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693715#M1093664</link>
      <description>&lt;P&gt;I can see interface alerts only from a few of the interfaces on the passive device. I am not sure why the alerts gets triggered on only those specific interfaces. When I check the events there is actually traffic on all interfaces.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Skärmklipp.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163383i14F88CACFF69741A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Skärmklipp.JPG" alt="Skärmklipp.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 14:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4693715#M1093664</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-09-26T14:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disable interface status alerts on the passive FTD in a failover p</title>
      <link>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4716917#M1094815</link>
      <description>&lt;P&gt;I discovered that the option to exclude health modules on the secondary device is available in 7.2. We can now even select individual interfaces to exclude which is great because we only want to exclude the interfaces that are missing a secondary IP address.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Skärmklipp.JPG" style="width: 205px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/167239i228C35DDBA38EC98/image-size/large?v=v2&amp;amp;px=999" role="button" title="Skärmklipp.JPG" alt="Skärmklipp.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 08:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-interface-status-alerts-on-the-passive-ftd-in-a-failover/m-p/4716917#M1094815</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-11-07T08:52:19Z</dc:date>
    </item>
  </channel>
</rss>

