Because the tunnel interface is a logical interface, it can’t indicate a physical
link status. Therefore, you must enable tunnel monitoring so that the tunnel
interface can verify connectivity to an IP address and determine if the path is
still usable. If the IP address is unreachable,
the firewall
can take action accordingly, that is, the firewall will either
wait for the tunnel to recover or
failover.
When a failover occurs, the existing tunnel is torn down, and routing changes are
triggered to set up a new tunnel and redirect
traffic. You
can specify the number of heartbeats to wait before taking the specified action. You
can also specify the interval between heartbeats to trigger the specified action.
For tunnel monitoring, a monitor status of down is an indicator that the destination
IP address being monitored is not reachable, and off indicates that the tunnel
monitor is not configured.