1.3 High Availability & Clustering Flashcards

1
Q

What is the main purpose of High Availability (HA) in Firepower?

A

To ensure network continuity by having a standby firewall take over if the active one fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary difference between Active/Standby and Active/Active HA modes?

A

Active/Standby has one active and one passive device, while Active/Active distributes traffic between multiple contexts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Cluster Control Link (CCL) used for in Firepower Clustering?

A

It synchronizes session state, configuration, and data flow information between clustered devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does intra-chassis clustering communicate between firewall instances?

A

It uses the backplane of the chassis instead of a separate physical link.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the key difference between Multi-Instance mode and Clustering?

A

Multi-Instance creates independent firewall instances, while Clustering combines multiple devices into a single firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the advantage of using Multi-Instance mode?

A

It allows multiple firewalls to run independently on the same hardware, increasing flexibility and efficiency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the role of a Port-Channel (EtherChannel) in Firepower?

A

It aggregates multiple physical links into a single logical link for redundancy and increased bandwidth.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why is EtherChannel important in High Availability deployments?

A

It provides link redundancy so traffic continues flowing if one link fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Firepower feature allows multiple security modules within a chassis to act as one firewall?

A

Intra-Chassis Clustering.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the main limitation of hardware bypass ports in Firepower?

A

They are only supported in Inline Sets and cannot be used in HA or Clustering modes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the primary difference between Active/Active and Active/Standby HA?

A

Active/Active distributes traffic between multiple firewalls, while Active/Standby has only one active firewall at a time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the role of security contexts in Active/Active HA?

A

Each context has its own routing and traffic processing rules, allowing firewalls to process traffic independently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which HA mode is best for environments requiring redundancy but not traffic load balancing?

A

Active/Standby HA, as it ensures failover without distributing traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does Firepower distribute traffic in Active/Active mode?

A

Traffic is assigned to different firewall units based on security contexts, ensuring even distribution across devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the main difference between Inter-Chassis and Intra-Chassis Clustering?

A

Inter-Chassis Clustering combines multiple physical Firepower appliances, while Intra-Chassis Clustering groups multiple security modules within a single chassis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How does Intra-Chassis Clustering synchronize information between members?

A

It uses the chassis backplane instead of a separate physical link like the CCL.

17
Q

Which clustering type allows multiple independent Firepower units to act as a single firewall?

A

Inter-Chassis Clustering.

18
Q

Which clustering type operates entirely within a single Firepower chassis?

A

Intra-Chassis Clustering.

19
Q

What is a key limitation of Intra-Chassis Clustering?

A

It is limited to the resources available within a single chassis and cannot expand across multiple appliances.