cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1892
Views
0
Helpful
1
Replies

Cisco Firepower Interface Monitoring for HA

Dear Community,

I had a question about interface monitoring for failover on the devices. I have a mix of port channels with sub-interfaces as well as individual interfaces. In terms of the port channels, should I be monitoring only the port channel or should I also monitor the subinteraces on the port channels as well? I cant think of a situation where one sub-interface on the port channel would go down while the others stay up, so I am not currently monitoring any of the subinterfaces, just the PC itself. Should I also be monitoring the subinterfaces?

 

Thanks.

1 Reply 1

I think it depends how you want to configure your failover sceanrio. By default, only physical interfaces are monitored automatically, so you will need to enable the monitoring on each of those virtual sub-interfaces. you can configure sub-interfaces monitored too, so you know if there's a layer-2 issue with the switch(es) your ASAs are uplinked to.

 

however, if you already monitoring the individual interface in case if these physical interface fail your ASA will failover to other unit. now if there is a blip on one of the sub-interface (false flag) than your active unit will failover to standby and standby will become active.

 

 

 

 

 

please do not forget to rate.
Review Cisco Networking for a $25 gift card