Define one or more path groups to monitor
specific destination addresses for the interface type. Add
Virtual Wire Path, and Add VLAN Path,
and Add Virtual Router Path. (If you have
Advanced Routing enabled, you can Add Logical Router Path). For
each type of path monitoring that you add, specify the following: Name—Select virtual wire, VLAN, or
virtual router* to monitor (drop-down choices are based on path
monitoring type you are adding). Source IP—For virtual wire and VLAN
interfaces, enter the source IP address to use in the pings sent
to the next-hop router (Destination IP address). The local router
must be able to route the address to the firewall. (The source IP
address for path groups associated with virtual routers* will be
automatically configured as the interface IP address that is indicated
in the route table as the egress interface for the specified destination
IP address.) Enabled—Enable monitoring of virtual
wire, VLAN, or virtual router*. Failure Condition: - Any (default)—Firewall
determines virtual wire, VLAN, or virtual router* has failed when
a ping failure in any destination IP group occurs.
- All—Firewall determines the virtual wire,
VLAN, or virtual router* has failed when a ping failure in all destination
IP groups occurs.
The actual HA failover is determined
by the Failure Condition you set for Path Monitoring, which considers
virtual wire, VLAN, and virtual router* path monitoring (whichever
you enabled).
Ping Interval—Specify the interval
between pings that are sent to the destination IP address (range
is 200 to 60,000ms; default is 200ms). Ping Count—Specify the number of failed
pings before declaring a failure (range is 3 to 10; default is 10).
*
If you have Advanced Routing enabled, Logical Router replaces Virtual
Router, and you can enable Logical Router Path Monitoring.
|