Fibre interface connection fails on primary FTD after adding to HA pair
Recently, we did a firewall change, which involved changing the connection on one of the interfaces (Guest) of the primary FTD (part of HA pair), from copper to fibre. The change was not successful. I have provided details below.
Prior to the change –
The secondary ftd was already in a failed state as its Guest interface connection was already using fibre connection, while the primary was on copper.
Due to this different interface type, the pair was not in HA and traffic was passing only through primary FTD.
During this time, the primary FTD was carrying production traffic.
During the change –
the HA pair had purposefully been broken down.
Connection on guest service interface of primary ftd was changed from copper to fibre.
firewall was successfully passing traffic.
As soon as, the FTD was added to HA, it went to failed state. The failover reason on the primary FTD was “no guest link”, even though physically it was connected. The interface status it was showing as down.
To isolate the issue on the primary, we made the secondary ftd as active firewall and vice versa.
Post the change –
the secondary firewall is currently passing production traffic, while the standby primary is in failed state.
Can anyone please advise what could have been the probable cause or how it can be fixed ? Thanks.
What is SecureX?
Cisco SecureX is included with all Secure Endpoint (formerly AMP for Endpoints) subscriptions. SecureX is a cloud-native platform that aggregates capabilities across your security environment. It’s designed to simplify your environment, ...
Cisco ISE Secure Wired Access Prescriptive Deployment Guide
Authors: Hariprasad Holla (until June 2018), Mahesh Nagireddy (until Dec 2018)
For an offline or printed copy of this document, simply choose ⋮ Options > Printer ...
Meet the Authors Slides- SecureX and the Evolution of Security Orchestration Automation and Response
(Live event – Wednesday, 20th, 2021 at 10:00 a.m. Pacific / 1:00 p.m. Eastern / 6:00 p.m. Paris)
This event had place on Wednesday 20th, January 202...
The following guide goes over the in and out of the Cisco Endpoints Security Analytics Dashboard as an overview and faq page
For more information on the product offering, licensing, support, and how to solution (TAC) guide links and more please visit the...
Join us live on Tuesday, January 19 at 10:00 am PT (and on demand after) as we discuss the latest version of ATT&CK and the expansion of TTPs in v8.
As a security expert, you are tasked with protecting your environment. You see the value of...