cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
358
Views
1
Helpful
1
Replies

FTD HA Reconfiguration via FMC

baxseliyevrahim
Level 1
Level 1

Hi dear Communities,I have configured Cisco FTD HA configuration on EVE-NG,

As I understand Standby ip in Monitored Interface is important to work HA properly.But I have question If we have 2 or 3 ISP Provider how many Failure Limit should uje?HA Monitored Interface.JPG

1 Accepted Solution

Accepted Solutions

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

   You decide via your configuration, upon which number of failed interfaces you'll perform failover. If you have three ISP's and your let's say primary ISP fails on the Active device, do you want to failover? If yes, set the your interface failover policy accordingly, so that failover happens upon any one monitored link failure. 

   If you think from perspective of the three ISP's, you might want to failover upon 2 of your ISP's failing, however this means you'll set your failover policy to be triggered upon 2 interface failures. What if your LAN / INSIDE link fails, it means you will no longer perform failover now, which clearly will result in network downtime.

    So, in general, unless you have redundant physical paths towards any zone of your network (WAN / LAN / DMZ), you would generally set the failover policy to 1 interface failure.

Thanks,

Cristian.

 

 

View solution in original post

1 Reply 1

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

   You decide via your configuration, upon which number of failed interfaces you'll perform failover. If you have three ISP's and your let's say primary ISP fails on the Active device, do you want to failover? If yes, set the your interface failover policy accordingly, so that failover happens upon any one monitored link failure. 

   If you think from perspective of the three ISP's, you might want to failover upon 2 of your ISP's failing, however this means you'll set your failover policy to be triggered upon 2 interface failures. What if your LAN / INSIDE link fails, it means you will no longer perform failover now, which clearly will result in network downtime.

    So, in general, unless you have redundant physical paths towards any zone of your network (WAN / LAN / DMZ), you would generally set the failover policy to 1 interface failure.

Thanks,

Cristian.

 

 

Review Cisco Networking for a $25 gift card