<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover methods Manual vs Link Down (traffic loss) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189171#M57301</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76850"&gt;@Trustnet&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not entirely sure what your question is, so this may not be the answer you are looking for exactly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Manual Failover:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Manual failover would only need to be done if you are not setting up either Link Monitoring&amp;nbsp;&lt;STRONG&gt;or&lt;/STRONG&gt; Path monitoring. If you are going to encure the&amp;nbsp;costs of having an Active/Passive system I'm not sure why you&amp;nbsp;&lt;EM&gt;wouldn't&amp;nbsp;&lt;/EM&gt;have at least one monitoring profile in place, if not both.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Manual failover is not going to be something you really want to go with; by the time someone logs into the firewall to manually issue the suspend command you'll have already interrupted&amp;nbsp;traffic to the organization, and that's if you notice it immediately.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Link Monitoring:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Link Monitoring is what I almost always see used by everyone if they only have one monitoring profile active. Link monitoring will do exactly what it sounds like, if the interface goes down it'll failover the traffic to the passive firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would setup Link Groups that specify the Group Failure condition, along with the interfaces. For example if ethernet1/2 was your inside link to your network cores you would likely want to failover to the passive firewall immeditely, you would likely do the same if you lost your DMZ link if you host external services. You might setup a lesser Link Group that would be set to a failure condition of 'all' if you have different zones for multiple different VPN connections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The downside to the Link Monitoring is that unless it's paired with a Path Monitoring profile you'll never experience&amp;nbsp;a failover if ethernet1/2 is still up, but traffic can not reach anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Path Monitoring:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Path monitoring&amp;nbsp;is something that should realistically&amp;nbsp;be a part of any HA setup, for the exact reasons that are mentioned above. Since Link Monitoring is simply monitoring the interface status, you will not experience&amp;nbsp;a failover if the ability to reach a host across that link goes down without the interface itself showing as down as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Path Monitoring separates&amp;nbsp;everything the same as Link Monitoring. So you can set it up that a failover event will take place if&amp;nbsp;&lt;EM&gt;all&lt;/EM&gt; Path Groups go down, or you can failover if&amp;nbsp;&lt;EM&gt;any&lt;/EM&gt; of the Path Groups go down. The advantage to the Path Group is that you can manually specify what Destination IP you are supposed to have access to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As an example of Path Monitoring I have three different Path Groups configured on all of my firewalls where applicable. The first checks outside connectivity to things like Google's DNS servers, OpenDNS, and a few other addresses that I have direct control over; if all of these connections ever return they are down it will trigger a failover event. I have similar policies setup for my internal and DMZ links. The only precaution&amp;nbsp;that you really need to take with Path Monitoring is that you don't want to have the Failure Condition set to 'Any' on a Path Group if you are monitoring servers that are not HA, as any maintenance would cause your firewall to failover as the Failure Condition would technically be met.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as a direct answer to the question of which one is faster, it's almost always going to be Link Monitoring&amp;nbsp;&lt;EM&gt;if&lt;/EM&gt; the link itself goes down. The possibility&amp;nbsp;of you being able to not only get the alert the link is down, get logged into the firewall, and either suspend the device through the GUI or issue the&amp;nbsp;&lt;EM&gt;request high-availability state suspend&lt;/EM&gt; command through the CLI before the Link Monitoring profile automatically suspends the firewall is next to nothing. Manual interaction will always be slower than letting the device take care of things itself.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2017 18:09:05 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-11-29T18:09:05Z</dc:date>
    <item>
      <title>Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189151#M57300</link>
      <description>&lt;P&gt;There are few triggers that could cause a failover in HA cluster.&lt;/P&gt;&lt;P&gt;I'm interested to&amp;nbsp;understand the difference between manual (graceful) and a hard failover like Link Down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a matter of network traffic loss, is there a difference between Link monitoring triggered failover and a manual failover? Meaning, &amp;nbsp;would the manual failover will cause less traffic loss than Link monitoring failover?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 16:36:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189151#M57300</guid>
      <dc:creator>Trustnet</dc:creator>
      <dc:date>2017-11-29T16:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189171#M57301</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76850"&gt;@Trustnet&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not entirely sure what your question is, so this may not be the answer you are looking for exactly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Manual Failover:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Manual failover would only need to be done if you are not setting up either Link Monitoring&amp;nbsp;&lt;STRONG&gt;or&lt;/STRONG&gt; Path monitoring. If you are going to encure the&amp;nbsp;costs of having an Active/Passive system I'm not sure why you&amp;nbsp;&lt;EM&gt;wouldn't&amp;nbsp;&lt;/EM&gt;have at least one monitoring profile in place, if not both.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Manual failover is not going to be something you really want to go with; by the time someone logs into the firewall to manually issue the suspend command you'll have already interrupted&amp;nbsp;traffic to the organization, and that's if you notice it immediately.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Link Monitoring:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Link Monitoring is what I almost always see used by everyone if they only have one monitoring profile active. Link monitoring will do exactly what it sounds like, if the interface goes down it'll failover the traffic to the passive firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would setup Link Groups that specify the Group Failure condition, along with the interfaces. For example if ethernet1/2 was your inside link to your network cores you would likely want to failover to the passive firewall immeditely, you would likely do the same if you lost your DMZ link if you host external services. You might setup a lesser Link Group that would be set to a failure condition of 'all' if you have different zones for multiple different VPN connections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The downside to the Link Monitoring is that unless it's paired with a Path Monitoring profile you'll never experience&amp;nbsp;a failover if ethernet1/2 is still up, but traffic can not reach anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Path Monitoring:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Path monitoring&amp;nbsp;is something that should realistically&amp;nbsp;be a part of any HA setup, for the exact reasons that are mentioned above. Since Link Monitoring is simply monitoring the interface status, you will not experience&amp;nbsp;a failover if the ability to reach a host across that link goes down without the interface itself showing as down as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Path Monitoring separates&amp;nbsp;everything the same as Link Monitoring. So you can set it up that a failover event will take place if&amp;nbsp;&lt;EM&gt;all&lt;/EM&gt; Path Groups go down, or you can failover if&amp;nbsp;&lt;EM&gt;any&lt;/EM&gt; of the Path Groups go down. The advantage to the Path Group is that you can manually specify what Destination IP you are supposed to have access to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As an example of Path Monitoring I have three different Path Groups configured on all of my firewalls where applicable. The first checks outside connectivity to things like Google's DNS servers, OpenDNS, and a few other addresses that I have direct control over; if all of these connections ever return they are down it will trigger a failover event. I have similar policies setup for my internal and DMZ links. The only precaution&amp;nbsp;that you really need to take with Path Monitoring is that you don't want to have the Failure Condition set to 'Any' on a Path Group if you are monitoring servers that are not HA, as any maintenance would cause your firewall to failover as the Failure Condition would technically be met.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as a direct answer to the question of which one is faster, it's almost always going to be Link Monitoring&amp;nbsp;&lt;EM&gt;if&lt;/EM&gt; the link itself goes down. The possibility&amp;nbsp;of you being able to not only get the alert the link is down, get logged into the firewall, and either suspend the device through the GUI or issue the&amp;nbsp;&lt;EM&gt;request high-availability state suspend&lt;/EM&gt; command through the CLI before the Link Monitoring profile automatically suspends the firewall is next to nothing. Manual interaction will always be slower than letting the device take care of things itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 18:09:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189171#M57301</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-29T18:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189359#M57328</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;My question is the difference between failovers regarding TRAFFIC LOSS.&lt;/P&gt;&lt;P&gt;Is the traffic loss the same in manual and automatic failover?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 14:30:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189359#M57328</guid>
      <dc:creator>Trustnet</dc:creator>
      <dc:date>2017-11-30T14:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189360#M57329</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76850"&gt;@Trustnet&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;A failover is a failover, regardless of whether it is triggered manually by yourself or automatically through the firewall HA monitoring the same commands are being issued. If there is any TRAFFIC LOSS it would be exactly the same regardless how the firewall failover is initiated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That being said if you have user noticable traffic loss during a failover event, you need to&amp;nbsp;evaluate your HA setup. If you follow best practices, depending on if you have L3 or L2 deployments, it shouldn't be noticable to your end-users that a failover event has even taken place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 14:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189360#M57329</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-30T14:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189361#M57330</link>
      <description>&lt;P&gt;So, based on what you are saying, assume I have the following scenario:&lt;/P&gt;&lt;P&gt;I need to change firewall connections to ports 1-4&lt;/P&gt;&lt;P&gt;So, I just disconnect them from the Primary (Active), replace and then the same for the secondary.&lt;/P&gt;&lt;P&gt;No need to manual&amp;nbsp;failover before disconnection of the cables&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 14:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189361#M57330</guid>
      <dc:creator>Trustnet</dc:creator>
      <dc:date>2017-11-30T14:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189364#M57331</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76850"&gt;@Trustnet&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you explain exactly what you are attempting to do in greater detail. It sounds like there is a much better way to do this, but I need to be sure of what exactly you are attempting to do before I start telling you to do something that isn't going to work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 15:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189364#M57331</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-30T15:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189367#M57333</link>
      <description>&lt;P&gt;Very&amp;nbsp;simple: replace cable for port 1 on both members&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 15:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189367#M57333</guid>
      <dc:creator>Trustnet</dc:creator>
      <dc:date>2017-11-30T15:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189369#M57335</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76850"&gt;@Trustnet&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay so this is a fairly simple failover event, and you would likely want to simply replace the cable on the passive unit, and then suspend the active firewall so that you can replace the cable on that unit when it isn't passing any traffic. You will just have to remember to go back and move the high-availability state to functional on the 'active' firewall that you suspended.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While removing port 1 would trigger a failover as long as it's in a Link Group that is actively being monitoring, manaul failover is recommended for maintenance as it isn't susceptable to any missconfiguration within the Link Monitoring or Link Group options, nor is it succeptable to poorly configured HA Timers that could interfere with HA event failover times.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 15:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189369#M57335</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-30T15:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189395#M57337</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76850"&gt;@Trustnet&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Very&amp;nbsp;simple: replace cable for port 1 on both members&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;mentioned when you're working on an "active" device it's probably "best" to just perform a fail-over anyway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said depending on your config pulling one port out isn't necessarily going to cause a HA / fail-over scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 4 links on my 5060s... 2 inside and 2 external links.&amp;nbsp; In our HA config we'd need to lose both links in a single group to cause an automated HA event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(This is from the "failure condition"&amp;nbsp; ANY or ALL on Link Group.&amp;nbsp; Coupled with the Link Monitoring of an "ANY."&amp;nbsp; If this we're "ALL" then all 4 of my interfaces would need to go down in order to fail-over which wouldn't be a good thing.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HA_Link_Monitoring.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12696i379D919BBC1BCB74/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="HA_Link_Monitoring.PNG" alt="HA_Link_Monitoring.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 18:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189395#M57337</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-11-30T18:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189608#M57382</link>
      <description>&lt;P&gt;So I will ask again, assuming HA configured right and all timers are perfectly configured, Why would I prefer manual failover over automatic? (&lt;STRONG&gt;&lt;U&gt;Again, assuming everything is working as expected&lt;/U&gt;&amp;nbsp; -&lt;/STRONG&gt; I'm not talking about any&lt;STRONG&gt;&amp;nbsp; &lt;/STRONG&gt;exceptional scenario&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;)&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2017 10:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189608#M57382</guid>
      <dc:creator>Trustnet</dc:creator>
      <dc:date>2017-12-03T10:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Failover methods Manual vs Link Down (traffic loss)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189614#M57386</link>
      <description>&lt;P&gt;Once&amp;nbsp;the&amp;nbsp;failover&amp;nbsp;condition&amp;nbsp;is&amp;nbsp;met(failure&amp;nbsp;is&amp;nbsp;detected),&amp;nbsp;the&amp;nbsp;time&amp;nbsp;it&amp;nbsp;takes&amp;nbsp;for&amp;nbsp;failover&amp;nbsp;should&amp;nbsp;be&amp;nbsp;same,&amp;nbsp;manual&amp;nbsp;or&amp;nbsp;automatic.&amp;nbsp;The&amp;nbsp;time&amp;nbsp;to&amp;nbsp;detect&amp;nbsp;the&amp;nbsp;failure&amp;nbsp;may&amp;nbsp;be&amp;nbsp;different&amp;nbsp;depending&amp;nbsp;on&amp;nbsp;the&amp;nbsp;type&amp;nbsp;of&amp;nbsp;the&amp;nbsp;failure&amp;nbsp;and&amp;nbsp;your&amp;nbsp;configuration&amp;nbsp;if&amp;nbsp;applicable&amp;nbsp;in&amp;nbsp;case&amp;nbsp;of&amp;nbsp;automatic&amp;nbsp;failure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending&amp;nbsp;on&amp;nbsp;the&amp;nbsp;failure&amp;nbsp;that&amp;nbsp;creates&amp;nbsp;the&amp;nbsp;failover,&amp;nbsp;automatic&amp;nbsp;failover&amp;nbsp;might&amp;nbsp;cause&amp;nbsp;more&amp;nbsp;packet&amp;nbsp;loss.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If&amp;nbsp;the&amp;nbsp;link&amp;nbsp;failure&amp;nbsp;happens&amp;nbsp;on&amp;nbsp;the&amp;nbsp;firewall&amp;nbsp;port,&amp;nbsp;meaning&amp;nbsp;that&amp;nbsp;the&amp;nbsp;port&amp;nbsp;on&amp;nbsp;the&amp;nbsp;firewall&amp;nbsp;is&amp;nbsp;disconnected&amp;nbsp;(not&amp;nbsp;the&amp;nbsp;remote&amp;nbsp;port&amp;nbsp;connected to&amp;nbsp;switch&amp;nbsp;router),&amp;nbsp;I&amp;nbsp;would&amp;nbsp;say&amp;nbsp;firewall&amp;nbsp;would&amp;nbsp;detect&amp;nbsp;it fairly&amp;nbsp;quickly.&amp;nbsp;In&amp;nbsp;such&amp;nbsp;a&amp;nbsp;case&amp;nbsp;the&amp;nbsp;failover&amp;nbsp;should&amp;nbsp;be triggered&amp;nbsp;immediately, just&amp;nbsp;like&amp;nbsp;suspend.&lt;BR /&gt;&lt;BR /&gt;If&amp;nbsp;your&amp;nbsp;network&amp;nbsp;does&amp;nbsp;not&amp;nbsp;tolerate&amp;nbsp;potential&amp;nbsp;latency&amp;nbsp;during&amp;nbsp;failover,&amp;nbsp;we&amp;nbsp;would&amp;nbsp;recommend&amp;nbsp;you&amp;nbsp;to&amp;nbsp;do&amp;nbsp;a&amp;nbsp;failover&amp;nbsp;test&amp;nbsp;to&amp;nbsp;make&amp;nbsp;sure&amp;nbsp;what&amp;nbsp;would&amp;nbsp;be&amp;nbsp;the&amp;nbsp;exact&amp;nbsp;delay&amp;nbsp;in&amp;nbsp;case a&amp;nbsp;failover&amp;nbsp;triggered&amp;nbsp;by&amp;nbsp;link&amp;nbsp;failure will&amp;nbsp;happen.&amp;nbsp;The&amp;nbsp;overall&amp;nbsp;end-user&amp;nbsp;impact&amp;nbsp;may&amp;nbsp;be&amp;nbsp;affected by surrounding&amp;nbsp;L2/L3&amp;nbsp;network&amp;nbsp;design&amp;nbsp;as well.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;But&amp;nbsp;if&amp;nbsp;you&amp;nbsp;need&amp;nbsp;to&amp;nbsp;failover&amp;nbsp;due&amp;nbsp;to&amp;nbsp;a&amp;nbsp;maintenance&amp;nbsp;activity&amp;nbsp;we&amp;nbsp;recommend&amp;nbsp;to&amp;nbsp;use&amp;nbsp;suspend&amp;nbsp;functionality.&amp;nbsp;It&amp;nbsp;is&amp;nbsp;easier&amp;nbsp;to&amp;nbsp;control&amp;nbsp;the&amp;nbsp;failover&amp;nbsp;via&amp;nbsp;suspend&amp;nbsp;and&amp;nbsp;the&amp;nbsp;failover&amp;nbsp;will&amp;nbsp;be&amp;nbsp;initiated&amp;nbsp;immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2017 15:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-methods-manual-vs-link-down-traffic-loss/m-p/189614#M57386</guid>
      <dc:creator>ET</dc:creator>
      <dc:date>2017-12-03T15:37:58Z</dc:date>
    </item>
  </channel>
</rss>

