
10-25
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Frequently Asked Failover Questions
LAN-Based Failover Questions
• What happens if the failover link is disconnected at startup?
The primary unit becomes active. The secondary unit uses other interfaces to detect if the primary
unit is active, and does not become active itself. If the primary unit is not active, then the secondary
unit waits a brief period before becoming active.
• What happens if the link goes down between the firewall and the switch after startup?
–
If the active unit’s failover interface goes down, it will failover to the standby unit. No additional
failovers can occur until the failover interface comes back up again.
–
If the standby unit’s failover interface goes down, an error message displays, but no failover
occurs. No failover can occur until the cable is reconnected.
• What happens if the failover link is not down, but does not pass traffic (for example, each
PIX
Firewall is connected to a separate switch and the link between the two switches is down)?
The PIX Firewalls use other interfaces to poll the peer status, but a failover is not triggered. If the
units detect other failover triggers, and a failover occurs, no additional failovers can occur until the
failover interface comes back up again.
• Can I use a crossover cable?
No, you must use a switch between the two units. We recommend that if your units are closer than
6 feet (which is when you would use a crossover cable), then you should use the serial failover cable.
You can use a crossover cable for the state link for Stateful Failover.
Stateful Failover Questions
• What information is not replicated to the standby PIX Firewall on Stateful Failover?
–
The user authentication (uauth) table.
–
The ISAKMP and IPSec SA table.
–
The ARP table.
–
Routing information.
–
Other UDP connections.
• What are Stateful Failover hardware requirements?
–
An Ethernet link dedicated to Stateful Failover.
–
Minimum 100 Mbps full duplex. On a PIX 535 with GE interfaces, you must use a GE interface
for the state link.
–
A connection using a crossover cable or a switch.
• Can I share the state link Ethernet interface with the failover link?
Yes, if you are connecting to a switch, and not using a crossover cable. However, we recommend
that you use a separate connection.
Comentarios a estos manuales