Tentative Hold Time (sec) | When a firewall in an HA active/active configuration
fails, it will go into a tentative state. The transition from tentative
state to active-secondary state triggers the Tentative Hold Time,
during which the firewall attempts to build routing adjacencies
and populate its route table before it will process any packets.
Without this timer, the recovering firewall would enter the active-secondary
state immediately and would silently discard packets because it
would not have the necessary routes (default is 60 seconds). |