<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco FTD Failover Behavior in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-failover-behavior/m-p/5257934#M1119393</link>
    <description>&lt;P&gt;Hello Guys,&lt;/P&gt;
&lt;P&gt;I am testing the active-passive failover in FTD. First of all the failover works fine for me, but I have query related to the timeouts I received during the testing. My testing process is as follows.&lt;/P&gt;
&lt;P&gt;Let’s say I have two FTDs, FTD-01 (primary unit) and FTD-02(Secondary Unit). In normal scenario FTD-01 is active and FTD-02 is standby.&lt;/P&gt;
&lt;P&gt;1. From my laptop I pinged 8.8.8.8 and then removed E1/1 from FTD-01. I received two request timeouts and then it started to ping.&lt;/P&gt;
&lt;P&gt;2. I reconnected the E1/1 to the FTD-01 and removed E1/1 from the FTD-02. I received 4 request timeouts and then it started to ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My concern is the difference in timeouts between step 1 and step 2. After failover to FTD-02, I immediately reconnected the E1/1 to FTD-01 and then removed E1/1 from FTD-02. I doubt this aggressive failover actions (without giving the ASA time to settle down) are causing the difference in the timeouts. Once the FTD-02 becomes active does it hold down for some time even if it detects an interface failure?.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Feb 2025 08:56:09 GMT</pubDate>
    <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
    <dc:date>2025-02-07T08:56:09Z</dc:date>
    <item>
      <title>Cisco FTD Failover Behavior</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-failover-behavior/m-p/5257934#M1119393</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;
&lt;P&gt;I am testing the active-passive failover in FTD. First of all the failover works fine for me, but I have query related to the timeouts I received during the testing. My testing process is as follows.&lt;/P&gt;
&lt;P&gt;Let’s say I have two FTDs, FTD-01 (primary unit) and FTD-02(Secondary Unit). In normal scenario FTD-01 is active and FTD-02 is standby.&lt;/P&gt;
&lt;P&gt;1. From my laptop I pinged 8.8.8.8 and then removed E1/1 from FTD-01. I received two request timeouts and then it started to ping.&lt;/P&gt;
&lt;P&gt;2. I reconnected the E1/1 to the FTD-01 and removed E1/1 from the FTD-02. I received 4 request timeouts and then it started to ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My concern is the difference in timeouts between step 1 and step 2. After failover to FTD-02, I immediately reconnected the E1/1 to FTD-01 and then removed E1/1 from FTD-02. I doubt this aggressive failover actions (without giving the ASA time to settle down) are causing the difference in the timeouts. Once the FTD-02 becomes active does it hold down for some time even if it detects an interface failure?.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 08:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-failover-behavior/m-p/5257934#M1119393</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2025-02-07T08:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Failover Behavior</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-failover-behavior/m-p/5258202#M1119408</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I think your tests are not the same .. I think you should let things stabilize.&lt;/P&gt;
&lt;P&gt;The firewall failover or flapping multiple times is not the feature is meant to serve although it works. The real use case is for a standby unit to takeover from a previous active unit.&lt;/P&gt;
&lt;P&gt;your step 1 is a simple failover from active unit to a standby unit&lt;/P&gt;
&lt;P&gt;your step 2 is actually a little more inolved - you are restoring a standby unit F1 that is not standby ready... it is not ready to take over immediately as it is in a failed state due to interface failure. For it to take over immedately, it should have been standby ready. So when you plug in f1 interface and immediately disconnect f2 interface, f1 as to start through a more elaborate process to elect it as active unit.&lt;/P&gt;
&lt;P&gt;see this guide&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/availability/high-availability/217763-troubleshoot-firepower-threat-defense-hi.html#toc-hId--1435216742" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/availability/high-availability/217763-troubleshoot-firepower-threat-defense-hi.html#toc-hId--1435216742&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I would suggest in your step2, to split into sub-tasks&lt;/P&gt;
&lt;P&gt;a) leave ftd2 as active unit&lt;/P&gt;
&lt;P&gt;b) plug ftd1 interrface and wait till it become standby ready&lt;/P&gt;
&lt;P&gt;c) now&amp;nbsp; disconnect ftd2 interrface&lt;/P&gt;
&lt;P&gt;i would think thatthe ping loss should be similar to step 1&lt;/P&gt;
&lt;P&gt;Hope that helps&lt;/P&gt;
&lt;P&gt;**Please rate helpful posts**&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2025 06:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-failover-behavior/m-p/5258202#M1119408</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-02-08T06:46:16Z</dc:date>
    </item>
  </channel>
</rss>

