14-14
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Understanding Failover
See the
“Failover Health Monitoring” section on page 14-16
for more information about interface and
unit monitoring.
Failover Actions
In an Active/Active failover configuration, failover occurs on a failover group basis, not a system basis.
For example, if you designate both failover groups as active on the primary unit, and failover group 1
fails, then failover group 2 remains active on the primary unit while failover group 1 becomes active on
the secondary unit.
Note
When configuring Active/Active failover, make sure that the combined traffic for both units is within the
capacity of each unit.
Table 14-2
shows the failover action for each failure event. For each failure event, the policy (whether
or not failover occurs), actions for the active failover group, and actions for the standby failover group
are given.
Table 14-2
Failover Behavior for Active/Active Failover
Failure Event
Policy
Active Group
Action
Standby Group
Action
Notes
A unit experiences a power or
software failure
Failover
Become standby
Mark as failed
Become active
Mark active as
failed
When a unit in a failover pair fails,
any active failover groups on that
unit are marked as failed and
become active on the peer unit.
Interface failure on active failover
group above threshold
Failover
Mark active
group as failed
Become active
None.
Interface failure on standby failover
group above threshold
No failover No action
Mark standby
group as failed
When the standby failover group is
marked as failed, the active failover
group does not attempt to fail over,
even if the interface failure
threshold is surpassed.
Formerly active failover group
recovers
No failover No action
No action
Unless configured with the
preempt
command, the failover
groups remain active on their
current unit.
Failover link failed at startup
No failover Become active
Become active
If the failover link is down at
startup, both failover groups on
both units become active.
Stateful Failover link failed
No failover No action
No action
State information becomes out of
date, and sessions are terminated if
a failover occurs.
Failover link failed during operation
No failover n/a
n/a
Each unit marks the failover
interface as failed. You should
restore the failover link as soon as
possible because the unit cannot fail
over to the standby unit while the
failover link is down.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......