• Network activity test: The failover node monitors the health of the firewalls by testing network activity. If all packets are not received with in 5 seconds of interval it detects failure (cisco 2008).
• ARP test: It also uses ARP (address resolution protocol) test, in ARP cache it checks the 10 recently learned entries in the memory. Then it sends an ARP request from cache entries, if the traffic is received in 5 seconds of time interval it consider the firewall is operational. If no traffic is received then its sends ARP request to the next entire of the cache. Likewise it checks all 10 entries in ARP cache, if not …show more content…
Stateful failover link uses logical update (LU) software that performs state replication through LAN interface into the standby device. As previously mentioned a stateful firewall caches the information of the connection established in state table. The state table stores the information TCP and UDP connection and it also stores the information of NAT (network address translation), H.323 and MGCP (multi gateway control point) connection and so on that are sent over stateful LAN interface to standby device. However by default stateful LAN interface do not replicate HTTP (TCP 80), it need manually configured using command failover replicate http. State replication provides uninterrupted service and zero downtime on network as it replicates the information to standby device. In active/standby failover mode, when stateful failover is configured it do not detect failure in first 15 seconds (default) it performs two consecutive check and then declare standby device as active. However stateful link can be configured with existing failover LAN interface, but this not recommended as it may cause disruption with failover