<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758278#M132676</link>
    <description>&lt;P&gt;Fo me it looks like "works as designed" ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;The INT-FW are probably the perimeter firewalls in your description. These have no clue that there is a change in&amp;nbsp;upstream-reachability. Because these are&amp;nbsp;independent systems, you should make sure that both INTFW can equally reach both DC1 and DC2 firewalls. Typically you achieve this with an additional (redundant) switch between these firewall systems.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Dec 2018 14:59:58 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2018-12-05T14:59:58Z</dc:date>
    <item>
      <title>firewall failover</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758188#M132672</link>
      <description>&lt;P&gt;Dears&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Please find the attached topology.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;I have some problem in understanding the fail over, whenever the port channel interface of DC-1 fails it shifts over to DC-2 FW but the perimeter firewalls doesn't shift and the traffic gets drops, hence if I m not wrong bydefault the failover should happen on perimeter as well please confirm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 11:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758188#M132672</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2019-03-12T11:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: firewall failover</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758196#M132673</link>
      <description>&lt;P&gt;Can you please clarify Which Port-channel we are referring ?&lt;/P&gt;&lt;P&gt;As long you are monitoring is configured with right interfaces and the failover condition met the requirements, it automatically fail-over to standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To confirm we need to understand your configuration also along with your diagram.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 12:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758196#M132673</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-12-05T12:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: firewall failover</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758278#M132676</link>
      <description>&lt;P&gt;Fo me it looks like "works as designed" ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;The INT-FW are probably the perimeter firewalls in your description. These have no clue that there is a change in&amp;nbsp;upstream-reachability. Because these are&amp;nbsp;independent systems, you should make sure that both INTFW can equally reach both DC1 and DC2 firewalls. Typically you achieve this with an additional (redundant) switch between these firewall systems.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 14:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758278#M132676</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-12-05T14:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: firewall failover</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758484#M132679</link>
      <description>&lt;P&gt;Dear&lt;/P&gt;&lt;P&gt;so you are confirming that we need a switch in between the DC firewall and Perimeter firewall to address such issue, there is no other solution that can help to solve this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advice.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 19:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758484#M132679</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-12-05T19:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: firewall failover</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758544#M132681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;As per you topology you need a switch in between DC-FW &amp;amp; INT-FW. Because when ever your AorB interface went down DC-FW switch-over and it will not affect the INT-FW because your&amp;nbsp;&lt;SPAN&gt;C,D,E,F interface are UP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;INT-FW Switch over occurs only when&amp;nbsp; C,D,E,F interface went down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Abheesh&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 21:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758544#M132681</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-12-05T21:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: firewall failover</title>
      <link>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758568#M132683</link>
      <description>&lt;P&gt;There is always more than one solution ... But in this scenario, the switch between the two firewall systems is the most common one and proven to work as expected.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 21:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-failover/m-p/3758568#M132683</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-12-05T21:49:21Z</dc:date>
    </item>
  </channel>
</rss>

