Configuring Secondary IP for FTD HA Interface Monitoring
A network administrator is setting up a new highly available Cisco Secure Firewall Threat Defense (FTD) pair. The administrator wants to monitor that the interfaces on the secondary Secure FTD are reachable not just up. What must the administrator configure?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
FTD high availability interface monitoring tests reachability rather than just link state only when a secondary (standby) IP address is configured.
When configuring a highly available Cisco Secure Firewall Threat Defense pair, interface health monitoring requires more than just link-state tracking. This page establishes that configuring a secondary IP address is necessary to ensure the active unit can perform network tests to verify the standby interface is fully reachable.
Choosing option A, assuming interface reachability monitoring happens by default when HA is enabled, rather than just link-state tracking.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To monitor that the interfaces on the secondary Secure FTD are reachable and not just physically up, the administrator must configure a secondary IP address. Without this standby IP, the active unit can only track the link state of the interface. Assigning a secondary IP allows the active unit to perform network tests to verify full IP reachability to the standby unit's interface. This ensures true end-to-end health monitoring for the high availability pair.Why the Other Options Are Wrong
Option A is incorrect because, by default, high availability only tracks the link state unless an IP address is configured for testing. Option C is incorrect because EUI-64 addressing is an IPv6 auto-configuration mechanism and is irrelevant to configuring HA interface health monitoring. Option D is incorrect because while separating high-availability and failover links is a best practice for redundancy, it does not dictate whether the system checks reachability versus simple link state.Community Comment Notes
As Kris92 noted, "Without a standby IP address, the active unit cannot perform network tests to check the standby interface health; it can only track the link state." This perfectly captures why the secondary IP address is mandatory for reachability testing. Other users agreed that option B is the correct choice based on this specific requirement for network testing.Exam Strategy
Distinguish between default HA behaviors (like link-state tracking) and configurations that enable advanced monitoring (like IP reachability). Remember that standby or secondary IP addresses are required for active units to perform network health tests on standby interfaces.