To prevent the HA pair from forwarding the same alert twice, each node in the pair adheres to the following rules:
The Sensor that received the attack packet on its monitoring port sends the signature alert to the Manager. (The Sensor that gets a copy of the attack packet from its failover peer does not send an alert.)
The Sensor forwarding the alert also takes the configured response action, such as sending a TCP reset.
The Sensor that has been online the longest is responsible for sending all reconnaissance and DoS alerts to the Manager.
In the event that both Sensors have been up for exactly the same amount time, the Sensor with the higher value serial number will be responsible for sending all reconnaissance and DoS alerts.
The reality check is that because the previous "stack" configuration results in attacks arriving on the monitoring ports of both Sensors (unless blocking is enabled), this configuration will cause some duplicate alerts to be generated. The details are as follows:
There will be no issue with reconnaissance and DoS attacks because one Sensor in a HA pair is always dedicated to send these alerts.
There will be no issue with TCP signature attacks either, due to the stateful nature of the scanning engine. That is, even though both Sensors will get the attack packet on their monitoring ports, the second Sensor will actually get the packet on its failover port first. When it subsequently gets the packet for a second time on its monitoring port, the packet will be recognized and treated as a duplicate packet. The duplicate packet will be forwarded along, but no alert will be generated.
However, because UDP and ICMP are not stateful, the same logic does not apply to those packets. Instead, UDP and ICMP attacks will create duplicate alerts in this configuration.