
11-7
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Understanding Failover
unit may be overwritten by the configuration being replicated from the active unit. Avoid entering
commands on either unit in the failover pair during the configuration replication process. Depending
upon the size of the configuration, replication can take from a few seconds to several minutes.
On the standby unit, the configuration exists only in running memory. To save the configuration to Flash
memory after synchronization:
• For single context mode, enter the copy running-config startup-config command on the active unit.
The command is replicated to the standby unit, which proceeds to write its configuration to Flash
memory.
• For multiple context mode, enter the copy running-config startup-config command on the active
unit from the system execution space and from within each context on disk. The command is
replicated to the standby unit, which proceeds to write its configuration to Flash memory. Contexts
with startup configurations on external servers are accessible from either unit over the network and
do not need to be saved separately for each unit. Alternatively, you can copy the contexts on disk
from the active unit to an external server, and then copy them to disk on the standby unit, where they
become available when the unit reloads.
Command Replication
Command replication always flows from the active unit to the standby unit. As commands are entered
on the active unit, they are sent across the failover link to the standby unit. You do not have to save the
active configuration to Flash memory to replicate the commands.
Note Changes made on the standby unit are not replicated to the active unit. If you enter a command on the
standby unit, the security appliance displays the message
**** WARNING **** Configuration
Replication is NOT performed from Standby unit to Active unit. Configurations are no
longer synchronized.
This message displays even when you enter many commands that do not affect
the configuration.
If you enter the write standby command on the active unit, the standby unit clears its running
configuration (except for the failover commands used to communicate with the active unit), and the
active unit sends its entire configuration to the standby unit.
For multiple context mode, when you enter the write standby command in the system execution space,
all contexts are replicated. If you enter the write standby command within a context, the command
replicates only the context configuration.
Replicated commands are stored in the running configuration. To save the replicated commands to the
Flash memory on the standby unit:
• For single context mode, enter the copy running-config startup-config command on the active unit.
The command is replicated to the standby unit, which proceeds to write its configuration to Flash
memory.
• For multiple context mode, enter the copy running-config startup-config command on the active
unit from the system execution space and within each context on disk. The command is replicated
to the standby unit, which proceeds to write its configuration to Flash memory. Contexts with startup
configurations on external servers are accessible from either unit over the network and do not need
to be saved separately for each unit. Alternatively, you can copy the contexts on disk from the active
unit to an external server, and then copy them to disk on the standby unit.
Comentarios a estos manuales