06-21-2023 03:48 AM
Hi Everyone,
We are in the process of deploying HA for 2 FTDs in our environment to go into production. Currently in the test phase, however, after deploying the HA, which worked. A week later, we lost the failover link. This caused the inability to deploy configuration changes to either FTD in the HA pair. I had to break the HA pair in order to deploy the latest config on the primary FTD, which means all config on the secondary HA pair was lost.
When the failover link fails, does FMC see both units as active and thereby making config deployment impossible?
I have attached the error message in this post as well
Someone kindly advise and assist.
06-21-2023 04:09 AM
dual brain issue, and since the mgmt interface also flapping during fail over then FMC see two FW with same mgmt interface.
06-21-2023 04:18 AM
Thanks, @MHM Cisco World for your response.
My worry is now that does this mean each time the failover link fails, the only way to be able to deploy is to break the HA pair and re-add the FTDs in HA when the failover link is repaired?
06-21-2023 06:38 AM
but Cisco FW HA is not depend only to failure link down to start failover process
it use Data interface IN and OUT to monitor mate FW before start process,
I think what you face is something relate to SW interconnect both FPR,
the FPR down the failure link and data interface that FPR use as monitoring interface.
06-27-2023 11:04 PM
Correct. However the problem is the failover link itself. The firewalls in HA pair are in separate locations connected by a fiber link.
06-21-2023 07:52 AM
I think the reason why the FMC wouldn't be able to push the changes when the failover is broken is because it wouldn't be able to know to which active device the changes should be pushed. Did you check from the logs why the failover link got broken? if not I would try to find out the root cause of why the failover link gets broken and try to fix that issue. Also, what version of FMC and FTD are on?
06-27-2023 11:02 PM
Yes that's my thinking too. So the scenarios is that we have the firewalls at different locations and the link connecting them is a fiber.
There was a fiber break that disrupted the failover link.
06-28-2023 03:29 AM
If you have multiple links between the two locations, you can configure a port channel for the HA links, in that case you will have some resiliency if a link goes down.
06-28-2023 03:32 AM
Cisco FW HA design not depend on Fail over Link only to detect mate down, it also use data interface INside and OUTside to send some heart beat to detect Mate down.
as I mention before I think fail over link and data link share same physical link when down all fail over and data interface is down.
06-21-2023 07:49 AM
The FTD dedicated management ports will still be with different IP addresses regardless of the failover state.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide