data:image/s3,"s3://crabby-images/3cefa/3cefa3859c67cb8aba2da31c8b0b98e6d352df1c" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 654"
B-30
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Appendix B Sample Configurations
Failover Example Configurations
access-list INTERNET extended permit ip any any
access-group INTERNET in interface inside
! Allows all inside hosts to access the outside for any IP traffic
The Secondary FWSM Configuration (Example 8)
You only need to configure the secondary FWSM to recognize the failover link. The secondary FWSM
obtains the context configurations from the primary FWSM upon booting or when
failover
is first
enabled. The
preempt
commands in the failover group configurations cause the failover groups to
become active on their designated unit after the configurations have been synchronized and the preempt
delay has passed.
Note that you must configure the
failover key
command on the secondary FWSM so that it can receive
the configuration from the primary FWSM.
failover
failover lan unit secondary
failover lan interface faillink vlan 10
failover key MySecretKey
failover interface ip faillink 192.168.253.1 255.255.255.252 standby 192.168.253.2
When you enable failover with the
failover
command, the secondary FWSM obtains the configuration
from the primary FWSM.
Switch Configuration (Example 8)
The following lines in the Cisco IOS switch configuration on both switches relate to the FWSM. For
information about configuring redundancy for the switch, see the switch documentation.
...
firewall multiple-vlan-interfaces
firewall module 1 vlan-group 1
firewall vlan-group 1 4-6,10,11,201,202
interface vlan 201
ip address 10.0.5.3 255.255.255.0
standby 200 ip 10.0.5.4
standby 200 priority 110
standby 200 preempt
standby 200 timers 5 15
standby 200 authentication Secret
no shutdown
interface vlan 202
ip address 10.0.9.3 255.255.255.0
standby 200 ip 10.0.9.4
standby 200 priority 110
standby 200 preempt
standby 200 timers 5 15
standby 200 authentication Secret
no shutdown
interface range gigabitethernet 2/1-3
channel-group 2 mode on
switchport trunk encapsulation dot1q
no shutdown
...
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......