The failure modes of the master to secondary arbiter failover process need to be analyzed a bit more. Especially if you have a packet of doom that takes out both the master and the secondary; what happens to all the network traffic when both are gone? Does it degrade to normal TCP (it didn't look like it).

