cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1752
Views
0
Helpful
2
Replies

Firepower HA Standby Interfaces show unassigned

Scott_22
Level 1
Level 1

I've noticed that unlike with ASA, the FTD appliances are not configured with a standby IP when the interfaces are configured. Instead, the secondary peer interfaces show as unassigned. Just to wrap my head around this - when the appliances fail over, the IPs are taken over by the secondary peer and it begins answering arp requests for them? 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Just like with ASA, you can optionally assign standby IP addresses to interfaces in an HA pair.

Either way, the newly active unit will send a gratuitous ARP when it takes over the active role so that the adjacent upstream and downstream devices recognize it as the "owner" of the active IP addresses.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Just like with ASA, you can optionally assign standby IP addresses to interfaces in an HA pair.

Either way, the newly active unit will send a gratuitous ARP when it takes over the active role so that the adjacent upstream and downstream devices recognize it as the "owner" of the active IP addresses.

Is there an advantage to adding the standby IP address over using only the single IP? Does it aid in the fail-over time when the peers fail-over between one another? 

Review Cisco Networking products for a $25 gift card