
10-24
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Frequently Asked Failover Questions
• How long does it take to detect a failure?
–
Network errors are detected within two consecutive polling intervals (by default, 15 second
intervals). The polling interval is user-configurable using the failover poll command.
–
(Cable-based only) Power failure and cable failure is detected immediately.
–
Failover communication errors are detected within two consecutive polling intervals.
• What maintenance is required?
Syslog messages are generated when any errors or switches occur. Evaluate the failed unit and fix
or replace it.
• Can you put a router between the PIX Firewall units?
No, all interfaces of the two units must be on the same subnet.
• Is it possible to have both PIX Firewall units become active at the same time?
Yes, in the following rare circumstances:
–
Cable-based failover only
–
The failover link is unplugged at startup
–
Both units have configurations in Flash memory
–
Both units have failover enabled
–
Both units have the UR license
In LAN-based failover, if the failover link is down, the secondary unit uses other interfaces to detect
if the primary unit is active, and does not become active itself.
• What prevents the standby unit from passing traffic?
The PIX Firewall failover feature ensures that only traffic aimed to the standby unit (hello packets,
Telnet if enabled) is successful, while traffic aimed through the unit is dropped.
Cable-Based Failover Questions
• What happens if the cable is disconnected at startup?
The primary unit becomes active. If the primary unit fails, the secondary unit does not become active
until the cable is reconnected.
Note that both units can become active in the following rare circumstances:
–
Both units have configurations in Flash memory
–
Both units have failover enabled
–
Both units have the UR license
• What happens if the cable becomes unplugged after startup?
The firewall generates a syslog message but no switching occurs. No failover can occur until the
cable is reconnected.
Comentarios a estos manuales