
11-3
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Understanding Failover
The Failover and State Links
This section describes the failover and the state links, which are dedicated connections between the two
units in a failover configuration. This section includes the following topics:
• Failover Link, page 11-3
• State Link, page 11-4
Failover Link
The two units in a failover pair constantly communicate over a failover link to determine the operating
status of each unit. The following information is communicated over the failover link:
• The unit state (active or standby).
• Power status (cable-based failover only—available only on the Cisco PIX security appliance
platform).
• Hello messages (keep-alives).
• Network link status.
• MAC address exchange.
• Configuration replication and synchronization.
Caution All information sent over the failover and Stateful Failover links is sent in clear text unless you secure
the communication with a failover key. If the security appliance is used to terminate VPN tunnels, this
information includes any usernames, passwords and preshared keys used for establishing the tunnels.
Transmitting this sensitive data in clear text could pose a significant security risk. We recommend
securing the failover communication with a failover key if you are using the security appliance to
terminate VPN tunnels.
On the PIX security appliance, the failover link can be either a LAN-based connection or a dedicated
serial Failover cable.
This section includes the following topics:
• LAN-Based Failover Link, page 11-3
• Serial Cable Failover Link (PIX Security Appliance Only), page 11-4
LAN-Based Failover Link
You can use any unused Ethernet interface on the device as the failover link. You cannot specify an
interface that is currently configured with a name. The failover link interface is not configured as a
normal networking interface; it exists only for failover communications. This interface should only be
used for the failover link (and optionally for the state link). You can connect the LAN-based failover link
by using a dedicated switch with no hosts or routers on the link or by using a crossover Ethernet cable
to link the units directly.
Note When using VLANs, use a dedicated VLAN for the failover link. Sharing the failover link VLAN with
any other VLANs can cause intermittent traffic problems and ping and ARP failures. If you use a switch
to connect the failover link, use dedicated interfaces on the switch and security appliance for the failover
link; do not share the interface with subinterfaces carrying regular network traffic.
Comentarios a estos manuales