cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
3
Helpful
5
Replies

HA on FTD

KayaaKashyap
Level 1
Level 1

Hi,

We have a greenfield project in which we are implementing FTD.

Let’s assume I have configured

Active : 192.168.75.10

standby : 192.168.75.11

FTD will connect to the SDWAN cedge devices (HA).

connectivity is as below:

SDWAN edge router (HA)—> FTD —> Core Switch —> internal servers

We will configure static route on firewall to reach SDWAN device.

And reverse traffic will reach to primary firewall which is 192.168.75.10

Now my question is during failover when standby firewall will be active. how the reverse traffic will reach to secondary firewall (192.168.75.12)?

 

 

 

2 Accepted Solutions

Accepted Solutions

SDWAN router need to have static route to active FW IP 
the FW IP is swap when fail over and hence always the SDWAN point to active FW 
MHM

View solution in original post

5 Replies 5

@KayaaKashyap both FTD's (Active/Standby) inside and outside interfaces need to be plugged into a switch and in the same VLAN. Upon failover of the Active (Primary) firewall, the Standby (Secondary) firewall will become active and the firewalls will swap IP addresses. So 192.168.75.10 will be the Active IP address regardless of whether the which firewall is passing traffic.

SDWAN router need to have static route to active FW IP 
the FW IP is swap when fail over and hence always the SDWAN point to active FW 
MHM

NOTE:- if you run IGP only the active participate in igp, the standby dont have any role.
MHM

This is helpful. Many thanks.

So we can say Primary IP of firewall works as VIP in FTD HA, right?

Please share if you have supportive document?

Review Cisco Networking for a $25 gift card