14-20
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Configuring Failover
•
Prerequisites, page 14-20
•
Configuring Cable-Based Active/Standby Failover (PIX 500 Series Security Appliance Only),
page 14-20
•
Configuring LAN-Based Active/Standby Failover, page 14-21
•
Configuring Optional Active/Standby Failover Settings, page 14-25
Prerequisites
Before you begin, verify the following:
•
Both units have the same hardware, software configuration, and proper license.
•
Both units are in the same mode (single or multiple, transparent or routed).
Configuring Cable-Based Active/Standby Failover (PIX 500 Series Security Appliance Only)
Follow these steps to configure Active/Standby failover using a serial cable as the failover link. The
commands in this task are entered on the
primary
unit in the failover pair. The primary unit is the unit
that has the end of the cable labeled “Primary” plugged into it. For devices in multiple context mode, the
commands are entered in the system execution space unless otherwise noted.
You do not need to bootstrap the secondary unit in the failover pair when you use cable-based failover.
Leave the secondary unit powered off until instructed to power it on.
Cable-based failover is only available on the PIX 500 series security appliance.
To configure cable-based Active/Standby failover, perform the following steps:
Step 1
Connect the Failover cable to the PIX 500 series security appliances. Make sure that you attach the end
of the cable marked “Primary” to the unit you use as the primary unit, and that you attach the end of the
cable marked “Secondary” to the other unit.
Step 2
Power on the primary unit.
Step 3
If you have not done so already, configure the active and standby IP addresses for each data interface
(routed mode), for the management IP address (transparent mode), or for the management-only
interface. The standby IP address is used on the security appliance that is currently the standby unit. It
must be in the same subnet as the active IP address.
Note
Do not configure an IP address for the Stateful Failover link if you are going to use a dedicated
Stateful Failover interface. You use the
failover interface ip
command to configure a dedicated
Stateful Failover interface in a later step.
hostname(config-if)#
ip address
active_addr netmask
standby
standby_addr
In routed firewall mode and for the management-only interface, this command is entered in interface
configuration mode for each interface. In transparent firewall mode, the command is entered in global
configuration mode.
In multiple context mode, you must configure the interface addresses from within each context. Use the
changeto context
command to switch between contexts. The command prompt changes to
hostname/
context
(config-if)#
, where
context
is the name of the current context. You must enter a
management IP address for each context in transparent firewall multiple context mode.
Step 4
(Optional) To enable Stateful Failover, configure the Stateful Failover link.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......