14-15
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Understanding Failover
Determining Which Type of Failover to Use
The type of failover you choose depends upon your security appliance configuration and how you plan
to use the security appliances.
If you are running the security appliance in single mode, then you can only use Active/Standby failover.
Active/Active failover is only available to security appliances running in multiple context mode.
If you are running the security appliance in multiple context mode, then you can configure either
Active/Active failover or Active/Standby failover.
•
To provide load balancing, use Active/Active failover.
•
If you do not want to provide load balancing, use Active/Standby or Active/Active failover.
Table 14-3
provides a comparison of some of the features supported by each type of failover
configuration:
Regular and Stateful Failover
The security appliance supports two types of failover, regular and stateful. This section includes the
following topics:
•
Regular Failover, page 14-15
•
Stateful Failover, page 14-15
Regular Failover
When a failover occurs, all active connections are dropped. Clients need to reestablish connections when
the new active unit takes over.
Stateful Failover
When Stateful Failover is enabled, the active unit continually passes per-connection state information to
the standby unit. After a failover occurs, the same connection information is available at the new active
unit. Supported end-user applications are not required to reconnect to keep the same communication
session.
The state information passed to the standby unit includes the following:
•
NAT translation table.
•
TCP connection states.
Table 14-3
Failover Configuration Feature Support
Feature
Active/Active
Active/Standby
Single Context Mode
No
Yes
Multiple Context Mode
Yes
Yes
Load Balancing Network Configurations
Yes
No
Unit Failover
Yes
Yes
Failover of Groups of Contexts
Yes
No
Failover of Individual Contexts
No
No
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......