I am for clarity in the time it takes for twos ASA's configured in active/passive using LAN-based stateful failover in routed mode to failover.
Switch1 -------------- Switch3
ASA1 ---failover link ----- ASA2
Switch2--------------- Switch 4
ASA1 is the active firewall and switch1 fails (hard down).
Does ASA2 have to wait for the holddown time, then all 4 failover tests (link up/down, Network activity, ARP, Broadcast ping) before failover actually occurs? Or is it simply that the expiry of the holddown time determines the actual failover time and the interface failover is simply used as a reporting mechanism for identification of failed interface?
Any help would be greatly appreciated.