Primary Traffic Failover to Secondary
-
Failover can occur instantaneously if the Secure Access or customer branch device initiates and successfully terminates the IKE tunnel or BGP session. Note: Terminating the IKE tunnel will terminate BGP as well.
-
In cases of communication failure between the branch device and Secure Access, traffic will switch to the secondary only if:
-
The Secure Access side DPD timeout occurs or BGP hold timer expires.
-
The customer's DPD timeout will not be effective in this situation as that won't result in tunnel termination on the Secure Access side.
-
The shorter of Secure Access DPD timeout (156 seconds max, default and non-negotiable) and BGP hold timer (90 seconds, default and negotiable) will apply.
For example: With a DPD timeout of 156 seconds and a BGP hold timer of 90 seconds, it would take at least 90 seconds for traffic to switch to the secondary tunnel.
-
-