[fw-wiz] pix firewall - failover and logging issues

From: Luciano Z (user_luciano@yahoo.com.br)
Date: 01/28/03


From: Luciano Z <user_luciano@yahoo.com.br>
To: firewall-wizards@honor.icsalabs.com
Date: Tue Jan 28 13:41:02 2003

Hi!

I have two questions about pix firewall for the list.

The first one is directed to failover users. I┤m using
a pix with version 6.1(1) software and with stateful
failover (I think this version needs update, right?).
From time to time I experiment lost of ssh connection
to the active pix because it have changed from active
state to standby state. I couldn┤t find the reason for
this because we just checked the cables and it was
operating well before I create another subnet attached
to this firewall, changing the address of and unused
interface.

In this situation I┤m not using LAN based failover
(this version doesn┤t support it) so the I have the
serial cable in place. Someone had some problem that
looks like my? Is it possible to start looging to the
syslog server just the messages related to failover
events?

Second question, this is about logging of URL access.
I┤ve read the pix could log the URLs accessed by the
users on a protected network. My question is about the
performace impact of this feature. Anybody used this?
What was the impression about it? And again: Is it
possible to log just the events related to this?

Well, thanks for your time!

[]
Luciano

_______________________________________________________________________
Busca Yahoo!
O servišo de busca mais completo da Internet. O que vocŕ pensar o Yahoo! encontra.
http://br.busca.yahoo.com/



Relevant Pages

  • Re: Pix fail-over questions
    ... Cisco PIX: Failover Demystified ... How to replace the primary PIX Firewall in a failover environment PIX ... secondarypix # show failover ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] RE: PIX FW Failover & Hello Packet
    ... Note you cannot configure failover if the units are not absolutely ... The hello packets are sent over all interfaces every 15 seconds, ... If the switch detects a bridge loop it will ... missed by the failover pix. ...
    (Firewall-Wizards)
  • Re: Pix fail-over questions
    ... Cisco PIX: Failover Demystified ... If that's the case then how do you ever upgrade the code or RAM ... This would definitely cause downtime due to the state table being lost ...
    (comp.dcom.sys.cisco)
  • Re: Failover Clarification
    ... - the backup must be able to distinguish between primary failure and failure of the communications path to the primary. ... The special PIX serial cable is designed to do number 1 keeping ... Stateful failover requires number 2 which in turn ...
    (comp.dcom.sys.cisco)
  • [NEWS] Cisco PIX Firewall Manager Password Disclosure Vulnerability
    ... Cisco PIX Firewall Manager Password Disclosure Vulnerability ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... standard Windows NT workstation or server that serves as the management ...
    (Securiteam)