Select the type or types of health monitoring you want to
perform so that you can control what happens if the security
chain experiences a failure.
You can select one, two, or all from Path
Monitoring, HTTP
Monitoring, and HTTP Monitoring
Latency.
Path Monitoring—Checks device
connectivity using pings.
HTTP Monitoring—Checks device
availability and response time.
HTTP Monitoring Latency—Checks device
processing speed and efficiency. When you select this
option, HTTP Monitoring is
automatically enabled as well.
Enabling one or more types of health monitoring activates the
On Health Check Failure options,
which determine how the firewall handles security chain
traffic if there is a security chain health failure.
If you configure multiple security chains on one set of
routed layer 3 Network Packet Broker interfaces, then on a
security chain failure, traffic fails over to the remaining
healthy security chains. If there is no security chain
available to handle failover traffic, the firewall takes the
action configured On Health Check
Failure. The options are Bypass
Security Chain and Block
Session.
Bypass Security Chain—The firewall
forwards the traffic to its destination instead of to the
security chain and the applies any configured Security
profiles and protections to the traffic.
Block Session—The firewall blocks the
session.
The method you select depends on how you want to treat the
traffic if you can’t run the traffic through the security
chain.