Cisco PIX 525 Spezifikationen Seite 164

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 163
11-32
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Configuring Failover
unit looks at the session information for any other interfaces with the same asr-group assigned to it. It
finds the session information in the outside interface for context A, which is in the standby state on the
unit, and forwards the return traffic to the unit where context A is active.
The traffic is forwarded though the outside interface of context A on the unit where context A is in the
standby state and returns through the outside interface of context A on the unit where context A is in the
active state. This forwarding continues as needed until the session ends.
Configuring Failover Communication Authentication/Encryption
You can encrypt and authenticate the communication between failover peers by specifying a shared
secret.
Caution All information sent over the failover and Stateful Failover links is sent in clear text unless you secure
the communication with a failover key. If the security appliance is used to terminate VPN tunnels, this
information includes any usernames, passwords and preshared keys used for establishing the tunnels.
Transmitting this sensitive data in clear text could pose a significant security risk. We recommend
securing the failover communication with a failover key if you are using the security appliance to
terminate VPN tunnels.
Enter the following command on the active unit of an Active/Standby failover pair or on the unit that has
failover group 1 active of an Active/Active failover pair:
hostname(config)# failover key
secret
The secret argument can be from 1 to 63 characters. The characters can be any combination of numbers,
letters, or punctuation.
Note To prevent the failover key from being replicated to the peer unit in clear text for an existing failover
configuration, disable failover on the active unit (or in the system execution space on the unit that has
failover group 1 in the active state), enter the failover key on both units, and then re-enable failover.
When failover is re-enabled, the failover communication will be encrypted with the key.
For new LAN-based failover configurations, the failover key command should be part of the failover
pair bootstrap configuration.
Verifying the Failover Configuration
This section describes how to verify your failover configuration. This section includes the following
topics:
Using the show failover Command, page 11-33
Viewing Monitored Interfaces, page 11-41
Displaying the Failover Commands in the Running Configuration, page 11-41
Testing the Failover Functionality, page 11-41
Seitenansicht 163
1 2 ... 159 160 161 162 163 164 165 166 167 168 169 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare