NGFW-ENGINEER · Question #111
After a recent high availability (HA) failover test on an active/passive cluster, an engineer noted a 30-45 second delay before traffic started flowing through a Link Aggregation Control Protocol…
The correct answer is C. Enable in HA passive state. Enabling LACP in the HA passive state allows the passive firewall to negotiate and maintain the LACP session with the switch before it becomes active, so when a failover occurs the aggregate is already formed and traffic can pass with minimal convergence delay.
Question
After a recent high availability (HA) failover test on an active/passive cluster, an engineer noted a 30-45 second delay before traffic started flowing through a Link Aggregation Control Protocol (LACP) aggregate interface on the newly active firewall. What should have been configured to support LACP pre-negotiation to minimize LACP convergence delay?
Options
- AEnable LACP fast failover.
- BSet LACP mode to passive.
- CEnable in HA passive state.
- DSet HA link monitoring to aggressive.
How the community answered
(42 responses)- A12% (5)
- B5% (2)
- C76% (32)
- D7% (3)
Explanation
Enabling LACP in the HA passive state allows the passive firewall to negotiate and maintain the LACP session with the switch before it becomes active, so when a failover occurs the aggregate is already formed and traffic can pass with minimal convergence delay.
Topics
Community Discussion
No community discussion yet for this question.