<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD HA - Unable to Deploy After Failover Link Broke in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859606#M1101838</link>
    <description>&lt;P&gt;The FTD dedicated management ports will still be with different IP addresses regardless of the failover state.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2023 14:49:50 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2023-06-21T14:49:50Z</dc:date>
    <item>
      <title>FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859376#M1101823</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;We are in the process of deploying HA for 2 FTDs in our environment to go into production. Currently in the test phase, however, after deploying the HA, which worked. A week later, we lost the failover link. This caused the inability to deploy configuration changes to either FTD in the HA pair. I had to break the HA pair in order to deploy the latest config on the primary FTD, which means all config on the secondary HA pair was lost.&lt;BR /&gt;&lt;BR /&gt;When the failover link fails, does FMC see both units as active and thereby making config deployment impossible?&lt;/P&gt;&lt;P&gt;I have attached the error message in this post as well&lt;BR /&gt;&lt;BR /&gt;Someone kindly advise and assist.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 10:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859376#M1101823</guid>
      <dc:creator>elijahosunbajo</dc:creator>
      <dc:date>2023-06-21T10:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859392#M1101825</link>
      <description>&lt;P&gt;dual brain issue, and since the mgmt interface also flapping during fail over then FMC see two FW with same mgmt interface.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 11:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859392#M1101825</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-21T11:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859399#M1101826</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My worry is now that does this mean each time the failover link fails, the only way to be able to deploy is to break the HA pair and re-add the FTDs in HA when the failover link is repaired?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 11:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859399#M1101826</guid>
      <dc:creator>elijahosunbajo</dc:creator>
      <dc:date>2023-06-21T11:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859530#M1101834</link>
      <description>&lt;P&gt;but Cisco FW HA is not depend only to failure link down to start failover process&lt;/P&gt;
&lt;P&gt;it use Data interface IN and OUT to monitor mate FW before start process,&amp;nbsp;&lt;BR /&gt;I think what you face is something relate to SW interconnect both FPR,&amp;nbsp;&lt;BR /&gt;the FPR down the failure link and data interface that FPR use as monitoring interface.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 13:38:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859530#M1101834</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-21T13:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859606#M1101838</link>
      <description>&lt;P&gt;The FTD dedicated management ports will still be with different IP addresses regardless of the failover state.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 14:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859606#M1101838</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T14:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859611#M1101840</link>
      <description>&lt;P&gt;I think the reason why the FMC wouldn't be able to push the changes when the failover is broken is because it wouldn't be able to know to which active device the changes should be pushed. Did you check from the logs why the failover link got broken? if not I would try to find out the root cause of why the failover link gets broken and try to fix that issue. Also, what version of FMC and FTD are on?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 14:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4859611#M1101840</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T14:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863651#M1102071</link>
      <description>&lt;P&gt;Yes that's my thinking too. So the scenarios is that we have the firewalls at different locations and the link connecting them is a fiber.&lt;BR /&gt;There was a fiber break that disrupted the failover link.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 06:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863651#M1102071</guid>
      <dc:creator>elijahosunbajo</dc:creator>
      <dc:date>2023-06-28T06:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863652#M1102072</link>
      <description>&lt;P&gt;Correct. However the&amp;nbsp;problem is the failover link itself. The firewalls in HA pair are in separate locations connected by a fiber link.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 06:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863652#M1102072</guid>
      <dc:creator>elijahosunbajo</dc:creator>
      <dc:date>2023-06-28T06:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863781#M1102096</link>
      <description>&lt;P&gt;If you have multiple links between the two locations, you can configure a port channel for the HA links, in that case you will have some resiliency if a link goes down.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 10:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863781#M1102096</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-28T10:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA - Unable to Deploy After Failover Link Broke</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863783#M1102097</link>
      <description>&lt;P&gt;Cisco FW HA design not depend on Fail over Link only to detect mate down, it also use data interface INside and OUTside to send some heart beat to detect Mate down.&amp;nbsp;&lt;BR /&gt;as I mention before I think fail over link and data link share same physical link when down all fail over and data interface is down.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 10:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-unable-to-deploy-after-failover-link-broke/m-p/4863783#M1102097</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-28T10:32:39Z</dc:date>
    </item>
  </channel>
</rss>

