Posted By Kepler Lam

When teaching the Cisco Firewall (ASA) course last week, there is a question about the port chnanel and failover policy. As for the failover policy, you can specify how many monitored interface fail will trigger the failover (default is one). The question is if port channel is being used, then will it treated as one single interface or as number of underlying physical interface.

Though not actually tested out, by using the ASDM wizard to setup failover, there is a screen to select the interface being monitored.

If you have created a port channel, you can only select the port channel interface to be monitored instead of the underlying physical interfaces, see figures below:

asa_int

asa_ha

That means, from the failover policy of view, it will just count the port channel interface as one single interface disregarding how many underlying physical interfaces it consists of.


 

 

 
Google

User Profile
Kepler Lam
Canada

 
Links
 
Category
 
Archives
 
Visitors

You have 528354 hits.

 
Latest Comments