cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
34666
Views
2
Helpful
1
Comments
Esha Goyal
Cisco Employee
Cisco Employee

"Fail-open" and "fail-close" are terms often used in network security and system design to describe how a system behaves in the event of a failure.

  1. Fail-Open: In a fail-open scenario, if a system or device fails, it automatically opens or allows access. This is usually used in systems where availability is prioritized over security. For instance, in a firewall setting, if the firewall fails, all network traffic would be allowed through.

  2. Fail-Close Aka Fail-secure: Conversely, in a fail-close scenario, if a system or device fails, it automatically closes or denies access. This is used in systems where security is prioritized over availability. Going back to the firewall example, if the firewall fails, all network traffic would be blocked.

In essence, the choice between fail-open and fail-close will depend on whether the system values availability or security more in the event of a failure.

Another example: Umbrella Mobile Devices can now be selected to Fail Open or Fail Closed. With these options, you can configure managed iOS and Android devices to block or allow access to the internet in the case of Umbrella protection failure.

Fail-close: This feature will block DNS traffic during network state changes OR when Umbrella DNS resolvers are determined to be unreachable.  

Fail-open: This feature will allow DNS traffic when Umbrella DNS resolvers are determined to be unreachable.

@cisco Umbrella

Comments
Benicio77
Level 1
Level 1

Fail-open and fail-close describe how systems behave during failures.

Fail-open allows access when a system fails, prioritizing availability over security. For example, if a firewall fails, traffic is allowed through.

Fail-close blocks access when a system fails, prioritizing security. For example, a failing firewall would block all traffic.

The choice depends on whether availability or security is more important. In Cisco Umbrella, fail-open lets DNS traffic through if resolvers are unreachable, while fail-close blocks it.

 
 
 
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: