09-26-2024 05:46 AM
Hi to all,
there is a port-channel interface that has various sub-interfaces (vlans).
The FTDs are in a high availability pair.
I have configured one specific vlan interface with primary and backup ip.
The problem i have is that when i disable this vlan interface (inside zone) although it is configured as monitored interface , it does not trigger the failover to the second ftd configured with the backup IP.
> show failover
Failover On
Failover unit Primary
Failover LAN Interface: FAILOVER-AND-STATE-LINK Ethernet1/12 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 2 of 1293 maximum
MAC Address Move Notification Interval not set
failover replication http
Version: Ours 9.18(4)210, Mate 9.18(4)210
Last Failover at: 19:19:42 UTC Sep 25 2024
This host: Primary - Active
Active time: 61025 (sec)
slot 0: FPR-2140 hw/sw rev (1.5/9.18(4)210) status (Up Sys)
Interface Eth-Trunk1 (0.0.0.0): Normal (Not-Monitored)
Interface vlan_3 (192.168.90.40/fe80::10): Normal (Monitored)
Interface vlan_27 (192.168.0.1/fe80::10): Normal (Monitored)
Interface diagnostic (0.0.0.0): Normal (Not-Monitored)
slot 1: snort rev (1.0) status (up)
slot 2: diskstatus rev (1.0) status (up)
Other host: Secondary - Standby Ready
Active time: 196928 (sec)
Interface Eth-Trunk1 (0.0.0.0): Normal (Not-Monitored)
Interface vlan_3 (192.168.90.41/fe80::10): Normal (Monitored)
Interface vlan_27 (192.168.0.2): Normal (Monitored)
Interface diagnostic (0.0.0.0): Normal (Not-Monitored)
slot 1: snort rev (1.0) status (up)
slot 2: diskstatus rev (1.0) status (up)
Finally a minimum of one interface is configured for the failover is configured as you can see in the png attached.
interface Port-channel1.3
vlan 3
nameif vlan_3
cts manual
propagate sgt preserve-untag
policy static sgt disabled trusted
security-level 0
ip address 192.168.90.40 255.255.255.0 standby 192.168.90.41
and
ip verify reverse-path interface vlan_3
Any ideas why is this not working?
Thanks
Ditter
09-29-2024 12:43 PM
I believe this is because you using sub-interface. check the failover scenarios :
also check some detailed explanation how that trigger occurs for failover :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide