Cisco PIX 525 Spezifikationen Seite 137

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 136
11-5
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Understanding Failover
Caution Sharing the Stateful Failover link with a regular firewall interface is not supported. This restriction was
not enforced in previous versions of the software. If you are upgrading from a previous version of the
security appliance software, and have a configuration that shares the state link with a regular firewall
interface, then the configuration related to the firewall interface will be lost when you upgrade. To
prevent your configuration from being lost, move the state link to a separate physical interface or disable
Stateful Failover before upgrading.
Note Enable the PortFast option on Cisco switch ports that connect directly to the security appliance.
The state traffic can be large. If you are using the failover link as the state link, you should use the fastest
Ethernet interface available. If you experience performance problems, consider dedicating a separate
link for the state traffic.
In multiple context mode, the state link resides in the system context. This interface and the failover
interface are the only interfaces in the system context. All other interfaces are allocated to and configured
from within security contexts.
Note The IP address and MAC address for the state link do not change at failover.
Caution All information sent over the failover and Stateful Failover links is sent in clear text unless you secure
the communication with a failover key. If the security appliance is used to terminate VPN tunnels, this
information includes any usernames, passwords and preshared keys used for establishing the tunnels.
Transmitting this sensitive data in clear text could pose a significant security risk. We recommend
securing the failover communication with a failover key if you are using the security appliance to
terminate VPN tunnels.
Active/Active and Active/Standby Failover
This section describes each failover configuration in detail. This section includes the following topics:
Active/Standby Failover, page 11-5
Active/Active Failover, page 11-9
Determining Which Type of Failover to Use, page 11-12
Active/Standby Failover
This section describes Active/Standby failover and includes the following topics:
Active/Standby Failover Overview, page 11-6
Primary/Secondary Status and Active/Standby Status, page 11-6
Device Initialization and Configuration Synchronization, page 11-6
Command Replication, page 11-7
Failover Triggers, page 11-8
Failover Actions, page 11-8
Seitenansicht 136
1 2 ... 132 133 134 135 136 137 138 139 140 141 142 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare