cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
670
Views
3
Helpful
4
Replies

cisco ASA fail-open with "no monitor-interface service-module"

Hi

In the ASA with firepower module, can we use fail-open command with "no monitor-interface service-module" ?
Can it still detect fail status of firepower module with "no monitor-interface service-module"

2 Accepted Solutions

Accepted Solutions

AViftrup
Level 1
Level 1

fail-open - means if module is down, it will forward traffic regardless of configured rules.

no monitor-interface service-module - This is only related to high-availability, executing this command means IF the SFR module is down, it will not failover to standby unit if this is the only condition to trigger.

Both commands can operate along each other, but keep in mind they have different use-cases.

View solution in original post

Marvin Rhoads
Hall of Fame
Hall of Fame

In addition to what @AViftrup correctly noted, the ASA will still see the status of the module even with "no monitor-interface service-module", it just won't trigger a failover event when the status changes to "failed". It will generate a syslog message whenever module status changes (assuming you haven't disabled logging).

View solution in original post

4 Replies 4

AViftrup
Level 1
Level 1

fail-open - means if module is down, it will forward traffic regardless of configured rules.

no monitor-interface service-module - This is only related to high-availability, executing this command means IF the SFR module is down, it will not failover to standby unit if this is the only condition to trigger.

Both commands can operate along each other, but keep in mind they have different use-cases.

thanks alot for attention .

 

Marvin Rhoads
Hall of Fame
Hall of Fame

In addition to what @AViftrup correctly noted, the ASA will still see the status of the module even with "no monitor-interface service-module", it just won't trigger a failover event when the status changes to "failed". It will generate a syslog message whenever module status changes (assuming you haven't disabled logging).

thanks alot for explanation

Review Cisco Networking for a $25 gift card