cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1057
Views
0
Helpful
7
Comments

Dear all,

 

We are planning to reboot 2 FTDs in cluster (master-slave), in documentation it says " High Availability is Unsupported Features with Clustering" but also found one more statement "Clustering provides high availability by monitoring chassis, unit, and interface health and by replicating connection states between units".

 

Cisco Firepower 4120 Threat Defense v6.2.3.4

 

Can someone guide me thorugh here?

 

 

 

7 Comments
balaji.bandi
Hall of Fame
Hall of Fame

How is your deployment, FP 4K series, can have multiple FTD instance can be used under 1 chassis.

 

give more information.

 

 

 

Muhammad Awais Khan
Cisco Employee
Cisco Employee

Hi,

 

" High Availability is Unsupported Features with Clustering" means that you cannot configure failover active-standby within the cluster or between cluster and non-cluster appliance.

 

Members within the cluster are providing active-active failover services as mentioned in the document "Clustering provides high availability by monitoring chassis, unit, and interface health and by replicating connection states between units".

 

In doc, it also states further: 

 

"When a unit in the cluster fails, the connections hosted by that unit are seamlessly transferred to other units; state information for traffic flows is shared over the control cluster link"

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_threat_defense_cluster_for_the_fxos_chassis.html

 

I would suggest restart the appliance one by one, you can start with any unit, master or slave. Wait for the restarted unit to come back, joined the cluster and then proceed with the second one.

@balaji.bandi 

Thanks for your comment.

 

Please find an output,

 

> show cluster info
Cluster XXX-XXX-XXX: On
Interface mode: spanned
This is "unit-1-1" in state MASTER
ID : 0
Site ID : 1
Version : 9.9(2)15
Serial No.: XXXXXXXXXXX
CCL IP : 0.0.0.0
CCL MAC : xxxx.xxxx.xxxx
Last join : XXXXX
Last leave: XXXXX
Other members in the cluster:
Unit "unit-2-1" in state SLAVE
ID : 1
Site ID : 1
Version : 9.9(2)15
Serial No.: XXXXXXXXXXX
CCL IP : 0.0.0.0
CCL MAC : xxxx.xxxx.xxxx
Last join : XXXXX
Last leave: XXXXX

@Muhammad Awais Khan 

Thanks for your comment.

 

We did reboot the slave device in the cluster, but we had a issue accessing internet till the slave device came up completely, but can't say the entire site is down only few of the connections didn't work, so guessing the connections handled by slave was stopped working.

 

We waited for almost 15 mins, the internet on the of the machine didn't work until the slave device came up, any thought on this?

Muhammad Awais Khan
Cisco Employee
Cisco Employee

The connections were dual-homed to Master-slave and part of ether-channel ? 

 

If it is part of ether-channel then there should no connection should have been disturbed at first place and if it happened then need more investigation.

 

If there are some connections on your appliances which are not part of port-channel and unique to each appliance then it is expected behavior. Those connections cannot be transfer.

@Muhammad Awais Khan 

Thanks for your input, it makes sense, let me verify the connections if it's part of Port-Channel.

 

Meanwhile do you have handy commands for cluster to check the configuration?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: