08-26-2020 03:11 AM
What's the best way to configure static active/passive MAC address for a failover pair?
Asking, because there are basically two ways:
1) Under FTD interface configuration -> Advanced -. Active/Standby Mac address.
It is then being applied like this during deploy:
FMC >> interface XYZ
FMC >> no mac-address
FMC >> mac-address xxxx.xxxx.xxxx standby yyyy.yyyy.yyyy
... which does not look too reliable, as negating and then re-applying it on EACH deployment and, given one case I'm researching, not sure if that is not even leading to some interruptions, but I won't jump to any conclusions yet.
2) Configuration under High Availability -> Interface MAC Address table.
It is then being applied like this during deploy:
FMC >> failover mac address XYZ xxxx.xxxx.xxxx yyyy.yyyy.yyyy
... again - on each deploy, but looks slightly cleaner as it is not negating and if the MAC hasn't changed, I'd say that re-applying this will not cause any issue. Haven't tried this out in a production.
If setting up both configuration options 1) comes first within the deploy and then when 2) follows, so the following Warning is shown:
ftd1 >> [info] : WARNING: MAC address already configured, single_vf interface IFNAME
...clearly using both of them does not look clean as well and is not even required as far as I see.
What's the best option here from reliability and stability perspective?
08-26-2020 03:39 AM
08-26-2020 03:48 AM
Thank you for input, but aren't both options eliminating service interruptions in case of failover? As per my understanding both options are used to configure active/standby MAC address and in case of failover they will behave the same way, but is there any behavioral difference then I'm not aware of?
08-26-2020 06:00 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide