
11-46
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Failover Configuration Examples
passwd iyymOglaKJgF2fx6 encrypted
telnet 192.168.2.45 255.255.255.255
hostname pixfirewall
access-list acl_out permit tcp any host 209.165.201.5 eq 80
failover
failover link state Ethernet3
failover ip address state 192.168.253.1 255.255.255.252 standby 192.168.253.2
global (outside) 1 209.165.201.3 netmask 255.255.255.224
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) 209.165.201.5 192.168.2.5 netmask 255.255.255.255 0 0
access-group acl_out in interface outside
route outside 0.0.0.0 0.0.0.0 209.165.201.4 1
LAN-Based Active/Standby Failover Example
Figure 11-3 shows the network diagram for a failover configuration using an Ethernet failover link.
Figure 11-3 LAN-Based Failover Configuration
Internet
209.165.201.4
192.168.254.1
192.168.253.1
192.168.254.2
192.168.253.2
192.168.2.5
192.168.2.1
209.165.201.1
209.165.201.2
192.168.2.2
Switch
Switch
Switch
failover
state
outside
inside
PAT: 209.165.201.3
Primary Unit
Secondary Unit
Static: 209.165.201.5
Web Server
126667
Kommentare zu diesen Handbüchern