The head's failover NIC pair is cabled to two ports on the same access switch; weeks later a firmware reboot takes that switch down and both NICs go dark together. Which cabling principle was missed?
Select an answer to reveal the explanation.
Short Explanation
Failover protects you from your own gear dying, not from the network's gear dying. Two NICs on one switch just means one switch to take both down — as that firmware reboot proved the hard way. Spread your pair across two switches so failover actually has somewhere to fail over to.
Full Explanation
A NIC failover pair defends against link and endpoint failure; the shared far end remains the dependency, and cabling design exists to remove it. With both members on one access switch, they share that switch's failure domain — firmware activation, power loss, configuration change — so the pair's failover collapses into reporting one common death instead of dodging it. The planning question is which single element kills both links at once, and here the answer was the switch; correct cabling lands the pair on separate switches, ideally with separate upstream paths, so each link remains independently removable without service loss. Different VLANs on the same switch fail by concept: VLANs segment traffic, not the device carrying them, and a firmware reboot on that device ends every VLAN it hosts simultaneously. Front-versus-rear ports on the head fail because distance across the appliance is irrelevant once the links converge inside a single far-end switch — diversity must exist where the shared risk is. A dark cold-spare link fails twice: the standby path never carries verified traffic so its health is assumed rather than known, and a correctly configured failover pair does not contend over one address anyway. Exam caveat: evaluate failover designs by hunting the common-mode element, not by counting cables. Operational check: each NIC of the pair lands on a different switch, and failover is exercised by shutting one port while the service is watched.