
1-24
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 1 Getting Started
PIX Firewall Failover
PIX Firewall Failover
The PIX Firewall failover feature lets you connect two identical PIX Firewall units with a special
failover cable to achieve a fully redundant firewall solution.
To configure the PIX Firewall failover feature, refer to Chapter 10, “Using PIX Firewall Failover.” For
instructions about upgrading failover from a previous version, refer to “Upgrading Failover Systems
from a Previous Version” in Chapter 11, “Changing Feature Licenses and System Software.”
Table 1-1 summarizes the support for the failover feature provided by different PIX Firewall models.
Ta b l e 1-1 Support for Failover
PIX Firewall Model Support for Failover
PIX 501 Not supported
PIX 506/506E Not supported
PIX 515/515E Requires additional license
PIX 525 Ships with full support
PIX 535 Ships with full support
When implementing failover, one unit functions as the active unit, while the other assumes the role of
the standby unit. Both units require the same configuration and run the same software version.
PIX Firewall Version 6.2 or higher supports failover between two units connected over a dedicated
Ethernet interface (LAN-based failover). LAN-based failover eliminates the need for a special failover
cable and overcomes the distance limitations imposed by the failover cable required to implement
failover on earlier versions of PIX
Firewall.
With failover, two PIX Firewall units synchronize configuration and session state information so that if
the active unit fails, the standby unit can assume its role without any interruption in network connectivity
or security.
Upgrading the PIX Firewall OS and License
The PIX Firewall software is a specialized, hardened operating system that is continuously being
improved to provide greater performance, security, and interoperability with Internet devices and
applications. For information about obtaining and installing the latest software release, refer to
Chapter 11, “Changing Feature Licenses and System Software.”
With PIX Firewall Version 6.2 or higher, you can upgrade your license without reinstalling the operating
system software. A new CLI command has been added to let you upgrade your activation key from the
command-line interface without reinstalling the software image and without entering monitor mode. For
detailed instructions, refer to
Chapter 11, “Changing Feature Licenses and System Software.”
You can use a Trivial File Transfer Protocol (TFTP) configuration server to obtain configuration for
multiple PIX
Firewall units from a central source. However, TFTP is inherently insecure so you should
not use it over networks where sharing privileged information in clear text is a violation of your network
security policy.
You can also use TFTP to download a .bin image from CCO to a PIX Firewall to upgrade or replace the
software image on the PIX
Firewall. TFTP does not perform any authentication when transferring files,
so a username and password on the remote host are not required.
Comentarios a estos manuales