- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-25-2020 10:32 PM
Hi All,
Referring my prior discussion Subject - "Firmware Updation A-P" , We have below configuration enabled on Link & path monitoring configuration at this moment, have a look on screen shot.
Will this be sufficient to trigger auto failover to Passive , if in case we can disconnect / disabled any of the directly connected interface from Active firewall Unit.
Thought to ask here to avoid any understanding gap.
09-26-2020 06:57 PM
You need to add the Ingress and Egress of the PA in the Link group.
We have single link to ISP and Linkagg to switch with 2 ports.
So in our case our Link group has 3 Interfaces and if anyone of those fails it will trigger the failover.
Regards
09-27-2020 12:46 AM
Hi @Jimmy20 ,
As @MP18 briefly explained - no, your setup is not sufficient to trigger failover. You have two "components" - to define conditions for the failover and to tell the firewall to use these conditions for failover. From the image you provide you have enabled the link and path monitor, but you have not configured any conditions, no interface to monitor.
It is good to mention the purpose of both link and path monitor. Link monitor will trigger failover if there is an issue with firewall interface, either if you disconnect it or there is no physical signal over the connected cable. Path monitor go beyond just looking at the physical state of your interfaces. With path monitor firewall will try to ping provided IP address trying to confirm that all three layers are up and running (imagine you have virtual fw, its interfaces way never go down, but there is not connectivity with its directly connected router, link monitor will not work here, but rather path monitor).
Link Monitor gives you very granular control over the condition when to trigger failover. If you notice you need to configure "Link group" in which you can group the physical interfaces in your interest. You need to select group failure condition, this means how many of the interfaces in the group needs to be down to consider the whole group as down. You can have multiple groups, so that is why you have "global" failure condition where you need to tell how many of your groups needs to be marked as down to trigger failover. How to group your interfaces and how to select the group and global failure condition depends on your setup.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!