nerdexam
Cisco

300-710 · Question #379

An engineer is deploying failover capabilities for a pair of Cisco Secure Firewall devices. The core switch keeps the MAC address of the previously active unit in the ARP table. Which action must…

The correct answer is A. Use a virtual MAC address on both units. When deploying failover capabilities for a pair of Cisco Secure Firewalls (often using the High Availability (HA) feature), it’s important that the MAC address seen by the network doesn't change during a failover. Using a virtual MAC address ensures that the same MAC address is…

Deployment

Question

An engineer is deploying failover capabilities for a pair of Cisco Secure Firewall devices. The core switch keeps the MAC address of the previously active unit in the ARP table. Which action must the engineer take to minimize downtime and ensure that network users keep access to the internet after a Cisco Secure Firewall failover?

Options

  • AUse a virtual MAC address on both units
  • BAdd the MAC address to the switch ARP table.
  • CSet the same MAC address on both units.
  • DRun a script to send gratuitous ARP after a failover.

How the community answered

(23 responses)
  • A
    70% (16)
  • B
    9% (2)
  • C
    4% (1)
  • D
    17% (4)

Explanation

When deploying failover capabilities for a pair of Cisco Secure Firewalls (often using the High Availability (HA) feature), it’s important that the MAC address seen by the network doesn't change during a failover. Using a virtual MAC address ensures that the same MAC address is presented to the network, regardless of which firewall unit (active or standby) is in control. This minimizes downtime because the core switch will continue to route traffic to the correct unit, as the virtual MAC address remains constant.

Topics

#Failover#High Availability#Virtual MAC#ARP

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice