14-2
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Understanding Failover
•
Regular and Stateful Failover, page 14-15
•
Failover Health Monitoring, page 14-16
•
Failover Feature/Platform Matrix, page 14-18
•
Failover Times by Platform, page 14-18
Failover System Requirements
This section describes the hardware, software, and license requirements for security appliances in a
failover configuration. This section contains the following topics:
•
Hardware Requirements, page 14-2
•
Software Requirements, page 14-2
•
License Requirements, page 14-2
Hardware Requirements
The two units in a failover configuration must have the same hardware configuration. They must be the
same model, have the same number and types of interfaces, the same amount of RAM, and, for the ASA
5500 series security appliance, the same SSMs installed (if any).
Note
The two units do not have to have the same size Flash memory. If using units with different Flash
memory sizes in your failover configuration, make sure the unit with the smaller Flash memory has
enough space to accommodate the software image files and the configuration files. If it does not,
configuration synchronization from the unit with the larger Flash memory to the unit with the smaller
Flash memory will fail.
Software Requirements
The two units in a failover configuration must be in the operating modes (routed or transparent, single
or multiple context). They have the same major (first number) and minor (second number) software
version. However, you can use different versions of the software during an upgrade process; for example,
you can upgrade one unit from Version 7.0(1) to Version 7.0(2) and have failover remain active. We
recommend upgrading both units to the same version to ensure long-term compatibility.
See
“Performing Zero Downtime Upgrades for Failover Pairs” section on page 41-6
for more
information about upgrading the software on a failover pair.
License Requirements
On the PIX 500 series security appliance, at least one of the units must have an unrestricted (UR) license.
The other unit can have a Failover Only (FO) license, a Failover Only Active-Active (FO_AA) license,
or another UR license. Units with a Restricted license cannot be used for failover, and two units with FO
or FO_AA licenses cannot be used together as a failover pair.
Note
The FO license does not support Active/Active failover.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......