
10-12
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Configuring LAN-Based Failover
Note If you are changing from cable-based failover to LAN-based failover, complete all the steps in the
following procedures that you did not already complete when you initially set up cable-based failover.
For example, you might need to configure the failover ip address command for the failover link, but
you do not need to reconfigure all the other failover IP addresses.
Configuring the Primary Unit
Follow these steps to configure the primary unit for LAN-based failover. Steps related only to
Stateful
Firewall are preceded by “(Stateful Failover).”
Note At any time during the procedure, you can enter the show failover command to see the failover status.
See the “Using the Show Failover Command” section for detailed information.
Step/Command Description
Step 1
If you have not done so already,
configure the Ethernet interface
you are using for the failover link:
Note these settings because you must use the same settings on the
secondary unit.
a.
primary(config)# interface
hardware_id hardware_speed
Enables the interface.
• hardware_id—ethernetn or gb-ethernetn.
• hardware_speed—The hardware speed and duplex for the
Ethernet interface. Do not use auto or 1000auto. Auto
detection is not always reliable, and PDM enforces this
setting.
–
10baseT—10 Mbps half duplex
–
10full—10 Mbps full duplex
–
100baseTX—100 Mbps half duplex
–
100full—100 Mbps full duplex
–
1000full—Auto negotiate, advertising 1000 Mbps full
duplex
–
1000full nonegotiate—Force link to 1000 Mbps full
duplex
For example:
primary(config)# interface ethernet2 100full
Kommentare zu diesen Handbüchern