Software Secure Access
Activity Manage

Primary Traffic Failover to Secondary

  • Failover can occur instantaneously if the Secure Access or customer branch device initiates and successfully terminates the IKE tunnel or BGP session. Note: Terminating the IKE tunnel will terminate BGP as well.

    • In cases of communication failure between the branch device and Secure Access, traffic will switch to the secondary only if:

      • The Secure Access side DPD timeout occurs or BGP hold timer expires.

      • The customer's DPD timeout will not be effective in this situation as that won't result in tunnel termination on the Secure Access side.

      • The shorter of Secure Access DPD timeout (156 seconds max, default and non-negotiable) and BGP hold timer (90 seconds, default and negotiable) will apply.

        For example: With a DPD timeout of 156 seconds and a BGP hold timer of 90 seconds, it would take at least 90 seconds for traffic to switch to the secondary tunnel.