Re: [fw-wiz] pix 515 failover

From: Carson Gaspar (carson@taltos.org)
Date: 09/06/02


From: Carson Gaspar <carson@taltos.org>
To: firewall-wizards@honor.icsalabs.com
Date: Fri Sep  6 06:19:27 2002


--On Friday, September 06, 2002 9:58 AM +0800 barry
<Barry.Haycock@b-online.com.au> wrote:

> i can setup the failover no problems but my question is
> when the pix fails over does the second one assume the ip address
> assigned to the interface on the primary or does it use the address
> assigned under the failover command for that interface.
>
> if the interface assumes the address assigned under the failover command
> how does one go about routing from a router etc to the firewall??

It's been a while, but I'm fairly certain the the standby PIX assumes both
the IP and MAC addresses of the active PIX during failover. I think it also
does a gratuitous ARP to update the CAM tables in the switches.

A simple network capture would answer this for certain.

-- 
Carson


Relevant Pages

  • Re: Pix fail-over questions
    ... Cisco PIX: Failover Demystified ... How to replace the primary PIX Firewall in a failover environment PIX ... secondarypix # show failover ...
    (comp.dcom.sys.cisco)
  • [fw-wiz] RE: PIX FW Failover & Hello Packet
    ... I have 2 PIX 515 fws and setup both of them to run as failover, ... have put the ACL on each interface except "Failover" interface. ... Is it possible the ACL blocks the communication when PIX tries to send the ...
    (Firewall-Wizards)
  • Failover problem with PIX 515
    ... with failover cable ... Cisco PIX Firewall Version 6.2 ... Normal Interface inside: Normal Other host: Secondary - ... Hardware is i82559 ethernet, address is 000b.46aa.a620 ...
    (comp.security.firewalls)
  • [fw-wiz] PIX failover disable help
    ... I have a pix stateful failoverset up in active/standby mode. ... Now i'm worried if by giving a shut on the interface on the ... As per the document i'm thinking of to disable the failover first and shut ...
    (Firewall-Wizards)
  • Re: [fw-wiz] pix 515 failover
    ... > i have been given the job of setting up failover for a pair of cisco pix 515 ... > to the interface on the primary ... The failover command assigned an IP address for the interface while ...
    (Firewall-Wizards)