<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Active/Standby polltime timers in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865677#M459046</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;Now the 'failover polltime interface msec 500 holdtime 5' command... does this tune the time that the ASA uses to test its other interfaces after it doesn't hear a hello from the standby on the failover interface?&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello this will let the ASA to send a hello packet each 500 msec and if he does not receive he will try to test the interfaces and if he does not receive any response on the next ( 5 times the poll time. 5*500:2500msec) failover will happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This setup is known as a subsecond failover, just to let you know the amount of hello packets that will be exchanged on your network will be a lot so you need to think about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Feb 2012 17:32:19 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-02-21T17:32:19Z</dc:date>
    <item>
      <title>ASA Active/Standby polltime timers</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865674#M459043</link>
      <description>&lt;P&gt;I understand the reason behind tuning these, but I have a few questions.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 10pt; "&gt;failover polltime unit msec 200 holdtime msec 800&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;failover polltime interface msec 500 holdtime 5 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;failover polltime unit msec 200 holdtime msec 800 -&amp;gt; I'm assuming this means if the Primary ASA has not heard from the Standby ASA&lt;/P&gt;&lt;P&gt;within 800 msec than it will attempt to failover to the standby device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a little confused about what the 'failover polltime interface msec 500 holdtime 5' is used for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand what it will send out hellos every 500 msec and the holdtime is 5 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question on the above example is, what is the interface polltime used for that the first polltime cannot provide?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:33:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865674#M459043</guid>
      <dc:creator>JohnTylerPearce</dc:creator>
      <dc:date>2019-03-11T22:33:09Z</dc:date>
    </item>
    <item>
      <title>ASA Active/Standby polltime timers</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865675#M459044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 10pt;"&gt;failover polltime unit msec 200 holdtime msec 800&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a unit does not hear hello packet on the&amp;nbsp; failover communication interface or cable for one polling period,&amp;nbsp; additional testing occurs through the remaining interfaces. If there is&amp;nbsp; still no response from the peer unit during the hold time, the unit is&amp;nbsp; considered failed and, if the failed unit is the active unit, the&amp;nbsp; standby unit takes over as the active unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover polltime interface msec 500 holdtime 5 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Use the&lt;STRONG&gt; failover polltime interface&lt;/STRONG&gt; command&amp;nbsp; to change the frequency that hello packets are sent out on data&amp;nbsp; interfaces. This command is available for Active/Standby failover only.&amp;nbsp; For Active/Active failover, use the &lt;STRONG&gt;polltime interface&lt;/STRONG&gt; command in failover group configuration mode instead of the&lt;STRONG&gt; failover polltime interface &lt;/STRONG&gt;command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1931234"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; You cannot enter a &lt;STRONG&gt;holdtime&lt;/STRONG&gt; value that is less&amp;nbsp; than 5 times the unit poll time. With a faster poll time, the adaptive&amp;nbsp; security appliance can detect failure and trigger failover faster.&amp;nbsp; However, faster detection can cause unnecessary switchovers when the&amp;nbsp; network is temporarily congested. Interface testing begins when a hello&amp;nbsp; packet is not heard on the interface for over half the hold time. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check this link for more details.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/ef.html#wp1931144"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/ef.html#wp1931144&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 15:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865675#M459044</guid>
      <dc:creator>Amit Rai</dc:creator>
      <dc:date>2012-02-21T15:34:32Z</dc:date>
    </item>
    <item>
      <title>ASA Active/Standby polltime timers</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865676#M459045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Please correct me if I'm wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'failover polltime unit msec 200 holdtime msec 800' means that that is the failover communication interface (failover cable going between ASAs) does not hear a hello within one polling period (200ms), than additional testing is done&lt;/P&gt;&lt;P&gt;through the remaining interfaces. If there is still no response within the holdtime timer (800ms), than if this is the&lt;/P&gt;&lt;P&gt;Active unit it will attempt to failover to the standby unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the 'failover polltime interface msec 500 holdtime 5' command... does this tune the time that the ASA uses to test its other interfaces after it doesn't hear a hello from the standby on the failover interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 15:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865676#M459045</guid>
      <dc:creator>JohnTylerPearce</dc:creator>
      <dc:date>2012-02-21T15:58:00Z</dc:date>
    </item>
    <item>
      <title>ASA Active/Standby polltime timers</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865677#M459046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;Now the 'failover polltime interface msec 500 holdtime 5' command... does this tune the time that the ASA uses to test its other interfaces after it doesn't hear a hello from the standby on the failover interface?&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello this will let the ASA to send a hello packet each 500 msec and if he does not receive he will try to test the interfaces and if he does not receive any response on the next ( 5 times the poll time. 5*500:2500msec) failover will happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This setup is known as a subsecond failover, just to let you know the amount of hello packets that will be exchanged on your network will be a lot so you need to think about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 17:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865677#M459046</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-21T17:32:19Z</dc:date>
    </item>
    <item>
      <title>ASA Active/Standby polltime timers</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865678#M459047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; You're probably going to want to punch me after this question...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover polltime unit msec 200 holdtime 800 msec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This statement means and the ASA will send a Hello out its Failover link every 200 msec, and if it does not get a response after one, it will wait the holdtime checking on its interfaces and then failing over to the standby.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if this is the case, why do I need the 'failover polltime interface' command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems like there doing the same thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If in the first command, it checkes the interfaces after it doesn't hear a hello, then what is the purpose of the interface&lt;/P&gt;&lt;P&gt;configuration command.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand the timing part just not how they operate together.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 21:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-polltime-timers/m-p/1865678#M459047</guid>
      <dc:creator>JohnTylerPearce</dc:creator>
      <dc:date>2012-02-21T21:10:34Z</dc:date>
    </item>
  </channel>
</rss>

