14-6
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Understanding Failover
Note
The IP address and MAC address for the Stateful Failover link does not change at failover unless the
Stateful Failover link is configured on a regular data interface.
Caution
All information sent over the failover and Stateful Failover links is sent in clear text unless you secure
the communication with a failover key. If the security appliance is used to terminate VPN tunnels, this
information includes any usernames, passwords and preshared keys used for establishing the tunnels.
Transmitting this sensitive data in clear text could pose a significant security risk. We recommend
securing the failover communication with a failover key if you are using the security appliance to
terminate VPN tunnels.
Active/Active and Active/Standby Failover
This section describes each failover configuration in detail. This section includes the following topics:
•
Active/Standby Failover, page 14-6
•
Active/Active Failover, page 14-10
•
Determining Which Type of Failover to Use, page 14-15
Active/Standby Failover
This section describes Active/Standby failover and includes the following topics:
•
Active/Standby Failover Overview, page 14-6
•
Primary/Secondary Status and Active/Standby Status, page 14-7
•
Device Initialization and Configuration Synchronization, page 14-7
•
Command Replication, page 14-8
•
Failover Triggers, page 14-9
•
Failover Actions, page 14-9
Active/Standby Failover Overview
Active/Standby failover lets you use a standby security appliance to take over the functionality of a failed
unit. When the active unit fails, it changes to the standby state while the standby unit changes to the
active state. The unit that becomes active assumes the IP addresses (or, for transparent firewall, the
management IP address) and MAC addresses of the failed unit and begins passing traffic. The unit that
is now in standby state takes over the standby IP addresses and MAC addresses. Because network
devices see no change in the MAC to IP address pairing, no ARP entries change or time out anywhere
on the network.
Note
For multiple context mode, the security appliance can fail over the entire unit (including all contexts)
but cannot fail over individual contexts separately.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......