<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Starting with code 9.4, you in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503361#M235727</link>
    <description>&lt;P&gt;Starting with &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html"&gt;code 9.4&lt;/A&gt;, you can specifically disable monitoring for certain interfaces such as management.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is also configured in the cluster configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;cluster group MyClusterGroup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&amp;nbsp;no health-check monitor-interface Management0/0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&amp;nbsp;no health-check monitor-interface Management0/1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2016 01:56:01 GMT</pubDate>
    <dc:creator>johnnylingo</dc:creator>
    <dc:date>2016-02-05T01:56:01Z</dc:date>
    <item>
      <title>ASA Cluster interface health check</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503359#M235720</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when deploying four ASA&amp;nbsp;firewalls in cluster mode, the health check monitoring cannot be customized like for Active/Passive setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, we&amp;nbsp;don't want a FW member to leave the cluster&amp;nbsp;if the management interface goes down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another example would be that all the interfaces in the FWs are port-channels, so we&amp;nbsp;don't want to have a unit removed from the cluster because 1 physical interface has gone down, and all the port channel still&amp;nbsp;up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;which are the commands to tune the interface health check when using four FWs in cluster mode?&lt;/P&gt;&lt;P&gt;Because we&amp;nbsp;assigned port channels as the cluster interface, will a FW member not be removed until the Port Channel goes down or anytime a phyical interface goes down the cluster member will be removed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503359#M235720</guid>
      <dc:creator>Jordi Benet</dc:creator>
      <dc:date>2019-03-12T04:36:26Z</dc:date>
    </item>
    <item>
      <title>Hi, By default in clustering</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503360#M235726</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default in clustering healthchecking is enabled....&lt;/P&gt;&lt;P&gt;Below mentioned excerpt from cisco document will be helpful.&lt;/P&gt;&lt;H2 class="pCRC_CmdRefCommand"&gt;health-check&lt;/H2&gt;&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1821139"&gt;&lt;/A&gt;To enab;e the cluster health check feature, use the &lt;B class="cBold"&gt; health-check &lt;/B&gt; command in cluster group configuration mode. To the health check, use the &lt;B class="cBold"&gt; no&lt;/B&gt; form of this command.&lt;/P&gt;&lt;P class="pCENB_CmdEnv_NoBold"&gt;&lt;A name="pgfId-1821140"&gt;&lt;/A&gt;&lt;B class="cBold"&gt; health-check &lt;/B&gt; [&lt;B class="cBold"&gt; holdtime&lt;/B&gt; &lt;EM class="cEmphasis"&gt; timeout&lt;/EM&gt; ] [&lt;B class="cBold"&gt; vss-enabled&lt;/B&gt; ]&lt;/P&gt;&lt;P class="pCENB_CmdEnv_NoBold"&gt;&lt;A name="pgfId-1821141"&gt;&lt;/A&gt;&lt;B class="cCN_CmdName"&gt; no &lt;/B&gt; &lt;B class="cBold"&gt; health-check &lt;/B&gt; [&lt;B class="cBold"&gt; holdtime&lt;/B&gt; &lt;EM class="cEmphasis"&gt; timeout&lt;/EM&gt; ] [&lt;B class="cBold"&gt; vss-enabled&lt;/B&gt; ]&lt;/P&gt;&lt;DIV&gt;&lt;H3 class="pCRSD_CmdRefSynDesc"&gt;&lt;A name="pgfId-1821147"&gt;&lt;/A&gt;&lt;/H3&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;Syntax Description&lt;DIV align="left"&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1821144"&gt;&lt;/A&gt;&lt;B class="cBold"&gt; holdtime&lt;/B&gt; &lt;EM class="cEmphasis"&gt; timeout&lt;/EM&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1821146"&gt;&lt;/A&gt;(Optional) Determines the amount of time between keepalive or interface status messages, between .8 and 45 seconds. The default is 3 seconds.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1841768"&gt;&lt;/A&gt;&lt;B class="cBold"&gt; vss-enabled&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1841780"&gt;&lt;/A&gt;If you configure the cluster control link as an EtherChannel (recommended), and it is connected to a VSS or vPC pair, then you might need to enable the &lt;B class="cBold"&gt; vss-enabled&lt;/B&gt; option. For some switches, when one unit in the VSS/vPC is shutting down or booting up, EtherChannel member interfaces connected to that switch may appear to be Up to the ASA, but they are not passing traffic on the switch side. The ASA can be erroneously removed from the cluster if you set the ASA holdtime timeout to a low value (such as .8 seconds), and the ASA sends keepalive messages on one of these EtherChannel interfaces. When you enable &lt;B class="cBold"&gt; vss-enabled&lt;/B&gt; , the ASA floods the keepalive messages on all EtherChannel interfaces in the cluster control link to ensure that at least one of the switches can receive them.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;H3 class="pCRCD_CmdRefCmdDefault"&gt;&lt;A name="pgfId-1821148"&gt;&lt;/A&gt;&lt;/H3&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;Command Default&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1821149"&gt;&lt;/A&gt;Health check is enabled by default, with a holdtime of 3 seconds.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;Regards&lt;/P&gt;&lt;P class="pB1_Body1"&gt;Karthik&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503360#M235726</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-08-13T12:47:18Z</dc:date>
    </item>
    <item>
      <title>Starting with code 9.4, you</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503361#M235727</link>
      <description>&lt;P&gt;Starting with &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html"&gt;code 9.4&lt;/A&gt;, you can specifically disable monitoring for certain interfaces such as management.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is also configured in the cluster configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;cluster group MyClusterGroup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&amp;nbsp;no health-check monitor-interface Management0/0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&amp;nbsp;no health-check monitor-interface Management0/1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 01:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-interface-health-check/m-p/2503361#M235727</guid>
      <dc:creator>johnnylingo</dc:creator>
      <dc:date>2016-02-05T01:56:01Z</dc:date>
    </item>
  </channel>
</rss>

