<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understanding Failover Link and State Link in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016570#M439204</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well I should have asked question different way. I have config for two pairs (one pair in one segment and another pair in another segment) and failover configuration is different in terms of one pair has two unique vlans being trunks across crossover cable - unique LAN failover vlan and state vlan while other pair only has one vlan for both purposes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAIR-1&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover Vlan100&lt;/P&gt;&lt;P&gt;failover polltime unit 15 holdtime 45&lt;/P&gt;&lt;P&gt;failover link failover Vlan100&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.1.1 255.255.255.252 standby 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAIR-2 &lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover Vlan300&lt;/P&gt;&lt;P&gt;failover polltime unit 1 holdtime 3&lt;/P&gt;&lt;P&gt;failover polltime interface 3&lt;/P&gt;&lt;P&gt;failover interface-policy 1&lt;/P&gt;&lt;P&gt;failover link stateful Vlan301&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.254.1 255.255.255.252 standby 192.168.254.2&lt;/P&gt;&lt;P&gt;failover interface ip stateful 192.168.254.5 255.255.255.252 standby 192.168.254.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According Cisco's failover configuration document you should have two vlans trunked across two chassis (ASA or FWSMs on 6500s). I am trying to understand what type of traffic "lan interface failover" vlan 300 in above config and "link stateful" vlan 301 in above config carry across? What is the best practice? should have uniqe vlans or just one vlan for both purposes? Sorry for not being clear on my initial question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 19 Aug 2012 03:42:46 GMT</pubDate>
    <dc:creator>amp512_nyph</dc:creator>
    <dc:date>2012-08-19T03:42:46Z</dc:date>
    <item>
      <title>Understanding Failover Link and State Link</title>
      <link>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016568#M439202</link>
      <description>&lt;P&gt;Whatt is the difference between failover link and state link in the context of Cisco FWSM? Why do I need both or what is the best practice? Thanks in advance. Just trying to understand.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016568#M439202</guid>
      <dc:creator>amp512_nyph</dc:creator>
      <dc:date>2019-03-11T23:43:42Z</dc:date>
    </item>
    <item>
      <title>Understanding Failover Link and State Link</title>
      <link>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016569#M439203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The difference is that the stateful link is the one in charge of handling the replication of the connections across the FWSM ( Used for the stateful failover) so if by any chance the device goes down the connections already established do not go down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 21:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016569#M439203</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-17T21:53:07Z</dc:date>
    </item>
    <item>
      <title>Understanding Failover Link and State Link</title>
      <link>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016570#M439204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well I should have asked question different way. I have config for two pairs (one pair in one segment and another pair in another segment) and failover configuration is different in terms of one pair has two unique vlans being trunks across crossover cable - unique LAN failover vlan and state vlan while other pair only has one vlan for both purposes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAIR-1&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover Vlan100&lt;/P&gt;&lt;P&gt;failover polltime unit 15 holdtime 45&lt;/P&gt;&lt;P&gt;failover link failover Vlan100&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.1.1 255.255.255.252 standby 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAIR-2 &lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover Vlan300&lt;/P&gt;&lt;P&gt;failover polltime unit 1 holdtime 3&lt;/P&gt;&lt;P&gt;failover polltime interface 3&lt;/P&gt;&lt;P&gt;failover interface-policy 1&lt;/P&gt;&lt;P&gt;failover link stateful Vlan301&lt;/P&gt;&lt;P&gt;failover interface ip failover 192.168.254.1 255.255.255.252 standby 192.168.254.2&lt;/P&gt;&lt;P&gt;failover interface ip stateful 192.168.254.5 255.255.255.252 standby 192.168.254.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According Cisco's failover configuration document you should have two vlans trunked across two chassis (ASA or FWSMs on 6500s). I am trying to understand what type of traffic "lan interface failover" vlan 300 in above config and "link stateful" vlan 301 in above config carry across? What is the best practice? should have uniqe vlans or just one vlan for both purposes? Sorry for not being clear on my initial question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2012 03:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016570#M439204</guid>
      <dc:creator>amp512_nyph</dc:creator>
      <dc:date>2012-08-19T03:42:46Z</dc:date>
    </item>
    <item>
      <title>Understanding Failover Link and State Link</title>
      <link>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016571#M439205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Atrey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well it is 100 % recommeded to use 2 different vlans ( FWSM) or 2 different interfaces (ASA) for the failover link and the state link between 2 units, this because of the amount of data being transfered on both of this links,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not all the time you have the oportunity to use 2 of them so that is why you can use only one, I have seen a lot of scenarios using just one and that works perfect but again if possible then use 2 &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is just a desing preference or optimization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2012 06:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/understanding-failover-link-and-state-link/m-p/2016571#M439205</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-19T06:14:25Z</dc:date>
    </item>
  </channel>
</rss>

