11-23-2022 06:01 AM - edited 11-23-2022 09:29 PM
Hi -
We have a multi context firewall with portchannel subinterfaces.
Is there a way to failover monitor the individual physical ethernets bundled into the portchannel?
So if one of the physical Ethernet links in the port-channel goes down, we want the firewall (all contexts) to fail over to the secondary firewall.
KR,
Adam
11-23-2022 09:38 AM
you have system/managment context access you can monitor that.
best we monitor switch side where they connected.
Monitor : i take it for utlisation - not failover monitor right ?
11-23-2022 09:24 PM
Hi - apologies if I was not clear. This is for failover monitoring. So if one of the physical Ethernet links in the port-channel goes down, we want the firewall to fail over to the secondary firewall.
11-24-2022 12:20 AM
The advantage of the port-channel is for the high availability,
take an example, if the port channel has 4 ports, even if 1 link goes down rest 3 work as expected.
for the sub-interface will not have that visibility. and work as expected.
until you context resource physically allocated and used in that context, you will not see a physical interface in the context at all.
good practice I have seen in the deployment is always monitor allocated interface (in your case sub interface to fail over)
Hope that helps you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide