09-22-2026 10:54 AM
My Cisco FTD keep sending me a critical alert every 5 minutes saying that a few of our FTD interface lack of input data:
Severity: critical
Module: Interface Status
Description: 2 subinterfaces of 'Port-channel20' are not receiving any packets
There are number of user wifi groups using firewalls interface and most of them are idle at all time. Therefore, there is nonstopable critical alerts send to all on call group to make them completed block all security alerts from FTD. And real issue, apparently get ignored.
My question is
1st, how to stop it. Do I have to exclude interface module or data module from alert?
2nd, is there anyway that I can keep other real critical staff such as server facing interface or internect facing interface is up/down, etc.
3rd, why Cisco consider lack of input as critical issue? Should this conidered as warning or notification issue? My understand the critical means Cisco feel this is major issue that need attention and should not be something that can keep it forever by acknolege it. Can Cisco classify temporary 100% CPU, or packet drop or lack of interface traffic as something different then service on call need to call someone at mid-night (like firewall node or ISP interface down etc)? If Cisco really think some interface is critical, can it be acknoledged and stop sending 1000 critical alert a day?
09-22-2026 11:27 AM
You can monitor using SNMP, SYSLOG, or NetFlow.
Sub-interfaces are monitored differently, but you can monitor the main PO interface.
Based on alert logs, you can exclude logs from the filter list.
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
09-22-2026 12:56 PM - edited 09-22-2026 12:58 PM
Hi
You can exclude specific interfaces from the check in the health policy. (From version 7.7 you can also exclude subinterfaces).
Another option (if you're running HA) is to configure a standby ip on the interfaces and enable monitoring, that causes the peers to send heartbeats which counts as traffic and as thus, the alert isn't triggered.
(Assuming you're running FMC, I don't know if it's possible with FDM)
09-22-2026 02:03 PM - edited 09-23-2026 10:42 AM
I wouldn’t disable the whole Interface Status module. If those Wi-Fi subinterfaces are intentionally idle, try excluding only those interfaces or lowering their alert severity while keeping critical monitoring for server/Internet-facing interfaces.
No traffic doesn’t always mean a failure, so repeated critical alerts can create unnecessary alert fatigue. Ideally, FTD should allow these conditions to be treated as warning/informational or suppressed/rate-limited while genuine interface-down events still page the on-call team.
09-23-2026 07:33 AM
Could you please show me how to lower the severity of this alert. I'd prefer this method better. I couldn't find myself how to do it. Thanks.
09-23-2026 10:39 AM
You may not be able to lower the severity directly on the interface itself. I’d check the FTD/FMC event or alert policy for Interface Status and see whether this specific “no input packets” condition can be filtered or suppressed for selected subinterfaces. If you can share your FTD/FMC version, someone may be able to point you to the exact setting.
🛡️🔧📡🚨💻✨
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide