14-27
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Configuring Failover
Enter the following command on the active unit to configure the virtual MAC addresses for an interface:
hostname(config)#
failover mac address
phy_if
active_mac
standby_mac
The
phy_if
argument is the physical name of the interface, such as Ethernet1. The
active_mac
and
standby_mac
arguments are MAC addresses in H.H.H format, where H is a 16-bit hexadecimal digit. For
example, the MAC address 00-0C-F1-42-4C-DE would be entered as 000C.F142.4CDE.
The
active_mac
address is associated with the active IP address for the interface, and the
standby_mac
is associated with the standby IP address for the interface.
There are multiple ways to configure virtual MAC addresses on the security appliance. When more than
one method has been used to configure virtual MAC addresses, the security appliance uses the following
order of preference to determine which virtual MAC address is assigned to an interface:
1.
The
mac-address
command (in interface configuration mode) address.
2.
The
failover mac address
command address.
3.
The
mac-address auto
command generated address.
4.
The burned-in MAC address.
Use the
show interface
command to display the MAC address used by an interface.
Configuring Active/Active Failover
This section describes how to configure Active/Active failover.
Note
Active/Active failover is not available on the ASA 5505 adaptive security appliance.
This section includes the following topics:
•
Prerequisites, page 14-27
•
Configuring Cable-Based Active/Active Failover (PIX 500 series security appliance), page 14-27
•
Configuring LAN-Based Active/Active Failover, page 14-29
•
Configuring Optional Active/Active Failover Settings, page 14-33
Prerequisites
Before you begin, verify the following:
•
Both units have the same hardware, software configuration, and proper license.
•
Both units are in multiple context mode.
Configuring Cable-Based Active/Active Failover (PIX 500 series security appliance)
Follow these steps to configure Active/Active failover using a serial cable as the failover link. The
commands in this task are entered on the
primary
unit in the failover pair. The primary unit is the unit
that has the end of the cable labeled “Primary” plugged into it. For devices in multiple context mode, the
commands are entered in the system execution space unless otherwise noted.
You do not need to bootstrap the secondary unit in the failover pair when you use cable-based failover.
Leave the secondary unit powered off until instructed to power it on.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......