04-12-2023 03:59 AM
Hi
I have x2 4115's in Active Passive HA.
On my FMC, I'm getting critical health alerts for the secondary/passive firewall "not receiving any packets" on some of its subinterfaces. Is this normal or a bug? Or an issue with my health monitoring policy? I would like to eliminate these alerts. I have another HA pair of 1140's on the same FMC and don't get this issue. Weird how it's only complaining about a few random subinterfaces?
Any help would be appreciated.
KR,
Adam
04-12-2023 05:15 AM
04-12-2023 05:32 AM
Hi - that thread is regarding ASA's with separate SFR modules. I am dealing with x2 FTD's in an HA pair. I dont want to disable interface monitoring for the HA Pair.
04-12-2023 05:36 AM
Yes friend I know the FW platform is different but in end the FMC is same.
this behave I think is similar.
04-12-2023 05:40 AM
I expected different behavior since the FMC is aware of the a/p HA and again why is it only complaining about 4 out of 9 sub-interfaces. Might be a bug then?
04-12-2023 05:42 AM
4 of 9 subinterface <<- are all are config as HA monitor ? if all then think contact TAC it can be bug and there is solution or workaround for it.
04-25-2023 05:23 AM
Hi - Yes they are enabled with failover monitoring.
04-12-2023 05:53 AM - edited 04-12-2023 05:54 AM
Symptom: Critical health alerts for Interface Status stating that interfaces are not receiving any packets are seen on the FMC for the standby FTD, which is not supposed to be processing traffic, so this is a normal and expected behavior.
Conditions: FTD deployed in High Availability.
Workaround: Blacklist the health alerts for Interface Status.
https://bst.cisco.com/bugsearch/bug/CSCvk05446
https://bst.cisco.com/bugsearch/bug/CSCvb36840
09-30-2024 01:46 PM
Hi all. Fixed by adding standby IP addresses to interfaces.
10-01-2024 08:06 AM
Enabling interface monitoring for failover with the inclusion of standby addresses is the best solution.
When that's not possible (e.g., HA pair sharing a /30 WAN address), newer versions of FMC will allow you to blacklist just one member of the HA pair for only some interfaces while continuing to monitor the interface on the Primary (and normally active) member..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide