14-32
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Configuring Failover
Enter the following commands to assign each context to a failover group:
hostname(config)#
context
context_name
hostname(config-context)#
join-failover-group {1 | 2}
hostname(config-context)#
exit
Step 6
Enable failover:
hostname(config)#
failover
Configure the Secondary Unit
When configuring LAN-based Active/Active failover, you need to bootstrap the secondary unit to
recognize the failover link. This allows the secondary unit to communicate with and receive the running
configuration from the primary unit.
To bootstrap the secondary unit in an Active/Active failover configuration, perform the following steps:
Step 1
(PIX 500 series security appliance only) Enable LAN-based failover:
hostname(config)#
failover lan enable
Step 2
Define the failover interface. Use the same settings as you used for the primary unit:
a.
Specify the interface to be used as the failover interface:
hostname(config)#
failover lan interface
if_name
phy_if
The
if_name
argument assigns a logical name to the interface specified by the
phy_if
argument. The
phy_if
argument can be the physical port name, such as Ethernet1, or a previously created
subinterface, such as Ethernet0/2.3. On the ASA 5505 adaptive security appliance, the
phy_if
specifies a VLAN.
b.
Assign the active and standby IP address to the failover link:
hostname(config)#
failover interface ip
if_name ip_addr mask
standby
ip_addr
Note
Enter this command exactly as you entered it on the primary unit when you configured the
failover interface.
The standby IP address must be in the same subnet as the active IP address. You do not need to
identify the standby address subnet mask.
c.
Enable the interface:
hostname(config)#
interface
phy_if
hostname(config-if)#
no shutdown
Step 3
(Optional) Designate this unit as the secondary unit:
hostname(config)#
failover lan unit secondary
Note
This step is optional because by default units are designated as secondary unless previously
configured otherwise.
Step 4
Enable failover:
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......