<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic interface shutdown in firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/interface-shutdown-in-firewall/m-p/1612464#M591777</link>
    <description>&lt;P&gt;if one out of few interface , monitored under failover, is shutdown on the primary firewall, what impact will it cause with failover of devices.&lt;/P&gt;&lt;P&gt;how will the connection be regained in such case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:50:24 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2019-03-11T19:50:24Z</dc:date>
    <item>
      <title>interface shutdown in firewall</title>
      <link>https://community.cisco.com/t5/network-security/interface-shutdown-in-firewall/m-p/1612464#M591777</link>
      <description>&lt;P&gt;if one out of few interface , monitored under failover, is shutdown on the primary firewall, what impact will it cause with failover of devices.&lt;/P&gt;&lt;P&gt;how will the connection be regained in such case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-shutdown-in-firewall/m-p/1612464#M591777</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T19:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: interface shutdown in firewall</title>
      <link>https://community.cisco.com/t5/network-security/interface-shutdown-in-firewall/m-p/1612465#M591780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default, when 1 out of the few ASA "monitored" interfaces are shutdown, it will failover to the standby unit within 5 seconds.&lt;/P&gt;&lt;P&gt;You can check which interfaces are monitored by issueing the "show monitor-interface" command, as not all interfaces are possibly configured to be monitored. ASA will only detect failure on "monitored" interfaces and if failure occurs on interface that is not being monitored, failover will not occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also change the policy on when failover occurs with the command: failover interface-policy [num/%]&lt;/P&gt;&lt;P&gt;You can configure it in such a way that only when 2 out of the 5 monitored interfaces are down to trigger the failover. However, if you are happy with the default of 1 monitored interface failure, then just leave it as default.&lt;/P&gt;&lt;P&gt;Here is the configuration guide for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/ha_active_standby.html#wp1116789"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/ha_active_standby.html#wp1116789&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the failover default times for different failures for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/ha_overview.html#wp1079158"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/ha_overview.html#wp1079158&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 22:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-shutdown-in-firewall/m-p/1612465#M591780</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-14T22:45:55Z</dc:date>
    </item>
  </channel>
</rss>

