cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
419
Views
5
Helpful
5
Replies

Cisco FTD Interface Alerts

JianfengWang5009
Frequent Visitor
Frequent Visitor

My Cisco FTD keep sending me a critical alert every 5 minutes saying that a few of our FTD interface lack of input data:

Severity: critical
Module: Interface Status
Description: 2 subinterfaces of 'Port-channel20' are not receiving any packets

There are number of user wifi groups using firewalls interface and most of them are idle at all time. Therefore, there is nonstopable critical alerts send to all on call group to make them completed block all security alerts from FTD. And real issue, apparently get ignored.

My question is

1st, how to stop it. Do I have to exclude interface module or data module from alert?

2nd, is there anyway that I can keep other real critical staff such as server facing interface or internect facing interface is up/down, etc.

3rd, why Cisco consider lack of input as critical issue? Should this conidered as warning or notification issue? My understand the critical means Cisco feel this is major issue that need attention and should not be something that can keep it forever by acknolege it. Can Cisco classify temporary 100% CPU, or packet drop or lack of interface traffic as something different then service on call need to call someone at mid-night (like firewall node or ISP interface down etc)? If Cisco really think some interface is critical, can it be acknoledged and stop sending 1000 critical alert a day?

 

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

You can monitor using SNMP, SYSLOG, or NetFlow.

Sub-interfaces are monitored differently, but you can monitor the main PO interface.

Based on alert logs, you can exclude logs from the filter list.

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

msc1011000
Level 4
Level 4

Hi

You can exclude specific interfaces from the check in the health policy. (From version 7.7 you can also exclude subinterfaces).

Another option (if you're running HA) is to configure a standby ip on the interfaces and enable monitoring, that causes the peers to send heartbeats which counts as traffic and as thus, the alert isn't triggered.

(Assuming you're running FMC, I don't know if it's possible with FDM)

garagedoorrepairdanville6
Community Member

I wouldn’t disable the whole Interface Status module. If those Wi-Fi subinterfaces are intentionally idle, try excluding only those interfaces or lowering their alert severity while keeping critical monitoring for server/Internet-facing interfaces.

No traffic doesn’t always mean a failure, so repeated critical alerts can create unnecessary alert fatigue. Ideally, FTD should allow these conditions to be treated as warning/informational or suppressed/rate-limited while genuine interface-down events still page the on-call team.

🛡️🔧📡🚨💻✨

Could you please show me how to lower the severity of this alert. I'd prefer this method better. I couldn't find myself how to do it. Thanks.

You may not be able to lower the severity directly on the interface itself. I’d check the FTD/FMC event or alert policy for Interface Status and see whether this specific “no input packets” condition can be filtered or suppressed for selected subinterfaces. If you can share your FTD/FMC version, someone may be able to point you to the exact setting.

🛡️🔧📡🚨💻✨

Review Cisco Networking for a $25 gift card