11-22-2016 04:44 AM - edited 03-12-2019 01:34 AM
Hi All,
Is anyone aware of a method to allow additional backup heartbeat if the failover link is down ?
Palo Alto offers this functionality .
Thanks
Solved! Go to Solution.
11-22-2016 03:08 PM
ASA uses both failover link and configured data interfaces for keepalive meesages. If 3 consecutive hello packets are missed it will send additional testing packets over the configured interfaces to determine the state of its interfaces.
Testing consists of the following four consecutive tests:
So basically if your failover link fails, you should still receive keep-alive packets via the data interfaces. If for whatever reason, 3 consecutive hello-packets are missed the 4 checks will be triggered to determine the interface state.
Hello packets use IP protocol 105 to exchange information.
11-22-2016 02:14 PM
Interface monitoring can be configured to send keep-alive messages over data interfaces (default for physical interfaces). In case of failover link going down, primary and secondary ASA are still able to exchange hello messages.
Let me know if this answers your question.
11-22-2016 02:44 PM
thanks for this but I thought interface monitoring is local to each firewall to see if its interface is up
for instance if you setup monitoring on interface inside and outside, it won't ping or send heartbeat over inside and outside but monitor them to ensure they are no going down.
the failover link will only change hello packets, by the way what protocol/port is the hello packet using ?
11-22-2016 03:08 PM
ASA uses both failover link and configured data interfaces for keepalive meesages. If 3 consecutive hello packets are missed it will send additional testing packets over the configured interfaces to determine the state of its interfaces.
Testing consists of the following four consecutive tests:
So basically if your failover link fails, you should still receive keep-alive packets via the data interfaces. If for whatever reason, 3 consecutive hello-packets are missed the 4 checks will be triggered to determine the interface state.
Hello packets use IP protocol 105 to exchange information.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide