|
|
This chapter includes the following sections:
Follow these steps to install a failover Standby unit.
Step 1 Follow the instructions in "Installing a PIX Firewall" to set up the Standby unit and connect its network interface cables.
Step 2 Locate the failover cable, shown in Figure 3-1. This cable is shipped separately from the PIX Firewall unit. The cable is labeled Primary on one end and Secondary on the other.
Install the cable for the PIX 515 as shown in Figure 3-1 or as shown in Figure 3-2 for the PIX 520 and earlier models.
Step 3 Connect the Primary end of the failover cable to the first PIX Firewall unit, that is, the one you have already configured. As soon as the PIX Firewall detects the presence of the failover cable, the system software enables failover mode and the PIX Firewall unit assumes active status.
Step 4 Connect the Secondary end of the failover cable to the Standby unit.
Step 5 Connect the Standby unit's power cord to the power connector on the rear panel of the unit, and to a power outlet.
Step 6 If you are using Stateful Failover, refer to Chapter 3, "Advanced Configurations" in the configuration guide for more information.
Connect one of the following between the dedicated interfaces on the PIX Firewall units:
(a) Cat 5 crossover cable directly connecting the Primary unit to the Secondary unit.
(b) 100BaseTX half-duplex hub using straight Cat 5 cables.
(c) 100BaseTX full-duplex on a dedicated switch or dedicated VLAN of a switch.
On the PIX 520, you can use Token Ring interfaces with Stateful Failover if the dedicated interface is 100BaseTX.
Figure 3-3 shows an example of a minimally configured PIX 515 with only the two interfaces on the motherboard used for network traffic.
Figure 3-4 shows the pinouts of a crossover cable, should you use this with the Stateful Failover dedicated interface.
Step 7 Turn on the Standby unit using the power switch at the back of the unit.
Within a few seconds, the Active unit automatically downloads its configuration to the Standby unit. The two units are now operating in failover mode. The first PIX Firewall (the one you configure) is the Primary unit, and is active by default. The second PIX Firewall is the Secondary unit, acting as failover Standby.
If the primary unit fails, the secondary unit automatically becomes active.
The Active unit automatically updates the configuration on the Standby unit. If the Standby unit has failed, updating takes place as soon as the Standby unit is brought back into operation.
Refer to Chapter 3, "Advanced Configurations," in the configuration guide for your respective software version listed in the section, "Related Documentation" in "About This Manual."
Should you need to test the cable you received, the pinouts are shown in Figure 3-5.
This section contains some frequently asked questions about the failover feature.
Refer to the "Failover" section in Chapter 3, "Advanced Configurations," in the configuration guide for your respective software version listed in the section, "Related Documentation" in "About This Manual."
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Posted: Fri Oct 15 18:53:53 PDT 1999
Copyright 1989-1999©Cisco Systems Inc.