
10-17
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Verifying the Failover Configuration
• Using the Show Failover Command, page 10-17
• Testing the Failover Functionality, page 10-20
See the “Monitoring Failover” section for other troubleshooting tools.
Using the Show Failover Command
On each unit, you can verify the failover status by entering:
primary(config)# show failover
This command shows:
• Whether failover is on or off
• Which unit is active
• The IP addresses assigned for the active and standby units
• The serial cable status
• The LAN cable status
• Stateful Failover statistics
Note The show interface display on the standby unit shows the active IP addresses associated with each
interfaces, even though the unit is using the failover IP addresses. Use the show failover command to
view the actual IP addresses being used.
See the following sample show failover command output. A description of each field follows.
pix(config)# show failover
Failover On
Serial Failover Cable status: My side not connected
Reconnect timeout 0:00:00
Poll frequency 15 seconds
Last Failover at: 18:32:16 UTC Mon Apr 7 2003
This host: Primary - Active
Active time: 510 (sec)
Interface 4th (172.16.1.1): Normal
Interface intf2 (192.168.2.1): Normal
Interface outside (192.168.1.1): Normal
Interface inside (10.1.1.1): Normal
Other host: Secondary - Standby
Active time: 0 (sec)
Interface 4th (172.16.1.2): Normal
Interface intf2 (192.168.2.2): Normal
Interface outside (192.168.1.2): Normal
Interface inside (10.1.1.2): Normal
Stateful Failover Logical Update Statistics
Link : 4th
Stateful Obj xmit xerr rcv rerr
General 0 0 0 0
sys cmd 0 0 0 0
up time 0 0 0 0
xlate 0 0 0 0
tcp conn 0 0 0 0
udp conn 0 0 0 0
ARP tbl 0 0 0 0
RIP Tbl 0 0 0 0
Comentarios a estos manuales