
11-24
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Configuring Failover
Note In multiple context mode, you must configure the interface addresses from within each context.
Use the changeto context command to switch between contexts. The command prompt changes
to hostname/
context
(config-if)#, where context is the name of the current context.
Step 4 (Optional) To enable Stateful Failover, configure the state link. The state link must be configured on an
unused interface.
a. Specify the interface to be used as state link.
hostname(config)# failover link
if_name
phy_if
The if_name argument assigns a logical name to the interface specified by the phy_if argument. The
phy_if argument can be the physical port name, such as Ethernet1, or a previously created
subinterface, such as Ethernet0/2.3. This interface should not be used for any other purpose (except,
optionally, the failover link).
b. Assign an active and standby IP address to the state link.
hostname(config)# failover interface ip
if_name ip_addr mask
standby
ip_addr
The standby IP address must be in the same subnet as the active IP address. You do not need to
identify the standby IP address subnet mask.
The state link IP address and MAC address do not change at failover. The active IP address always
stays with the primary unit, while the standby IP address stays with the secondary unit.
c. Enable the interface.
hostname(config)# interface
phy_if
hostname(config-if)# no shutdown
Step 5 Configure the failover groups. You can have at most two failover groups. The failover group command
creates the specified failover group if it does not exist and enters the failover group configuration mode.
For each failover group, you need to specify whether the failover group has primary or secondary
preference using the primary or secondary command. You can assign the same preference to both
failover groups. For load balancing configurations, you should assign each failover group a different unit
preference.
The following example assigns failover group 1 a primary preference and failover group 2 a secondary
preference:
hostname(config)# failover group 1
hostname(config-fover-group)# primary
hostname(config-fover-group)# exit
hostname(config)# failover group 2
hostname(config-fover-group)# secondary
hostname(config-fover-group)# exit
Step 6 Assign each user context to a failover group using the join-failover-group command in context
configuration mode.
Any unassigned contexts are automatically assigned to failover group 1. The admin context is always a
member of failover group 1.
Enter the following commands to assign each context to a failover group:
hostname(config)# context
context_name
hostname(config-context)# join-failover-group {1 | 2}
hostname(config-context)# exit
Comentarios a estos manuales