08-10-2014 02:20 AM - edited 03-11-2019 09:36 PM
Hi,
when deploying four ASA firewalls in cluster mode, the health check monitoring cannot be customized like for Active/Passive setup?
For example, we don't want a FW member to leave the cluster if the management interface goes down.
Another example would be that all the interfaces in the FWs are port-channels, so we don't want to have a unit removed from the cluster because 1 physical interface has gone down, and all the port channel still up.
which are the commands to tune the interface health check when using four FWs in cluster mode?
Because we assigned port channels as the cluster interface, will a FW member not be removed until the Port Channel goes down or anytime a phyical interface goes down the cluster member will be removed?
Thank you very much.
Regards,
J
08-13-2014 05:47 AM
Hi,
By default in clustering healthchecking is enabled....
Below mentioned excerpt from cisco document will be helpful.
To enab;e the cluster health check feature, use the health-check command in cluster group configuration mode. To the health check, use the no form of this command.
health-check [ holdtime timeout ] [ vss-enabled ]
no health-check [ holdtime timeout ] [ vss-enabled ]
02-04-2016 05:56 PM
Starting with code 9.4, you can specifically disable monitoring for certain interfaces such as management.
This is also configured in the cluster configuration.
cluster group MyClusterGroup
no health-check monitor-interface Management0/0
no health-check monitor-interface Management0/1
!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: