|
|
This chapter includes the following sections:
This chapter does not apply to the PIX 506 or to the PIX 515 with an "R" (restricted) license.
Follow these steps to install a failover Standby unit:
Step 2 Locate the failover cable, shown in Figure 3-1. This cable is shipped separately from the PIX Firewall unit. The cable is labeled Primary on one end and Secondary on the other.
Install the cable for the PIX 515 as shown in Figure 3-1 or as shown in Figure 3-2 for the PIX 520 and earlier models.


Step 3 Connect the Primary end of the failover cable to the first PIX Firewall unit, that is, the one you have already configured. As soon as the PIX Firewall detects the presence of the failover cable, the system software enables failover mode and the PIX Firewall unit assumes active status.
Step 4 Connect the Secondary end of the failover cable to the Standby unit.
Step 5 Connect the Standby unit's power cord to the power connector on the rear panel of the unit, and to a power outlet.
Step 6 If you are using Stateful Failover, refer to Chapter 3, "Advanced Configurations" in the configuration guide for your respective software version referenced in the section, "Related Documentation" in "About This Manual."
Use one of the following types of connections, that is appropriate for your system, between the dedicated interfaces on the PIX Firewall units:
On the PIX 520, you can use Token Ring interfaces with Stateful Failover if the dedicated interface is 100BaseTX.
Figure 3-3 shows an example of a minimally configured PIX 515 with only the two interfaces on the motherboard used for network traffic.

![]() |
Note All enabled interfaces must be connected between the Active and Standby units. If an interface is not in use, use the shutdown option to the interface command to disable the interface. |
Figure 3-4 shows the pinouts of a crossover cable, should you use this with the Stateful Failover dedicated interface.

Step 7 Power on the Standby unit using the power switch at the back of the unit.
Within a few seconds, the Active unit automatically downloads its configuration to the Standby unit. The two units are now operating in failover mode. The first PIX Firewall (the one you configure) is the Primary unit, and is active by default. The second PIX Firewall is the Secondary unit, acting as failover Standby.
If the Primary unit fails, the Secondary unit automatically becomes active.
![]() |
Note Only configure the Active unit. On a PIX 515, the Active unit is indicated by the ACT LED on the front of the unit. On a PIX 520, you can access the console and determine which unit is active with the show failover command. |
The Active unit automatically updates the configuration on the Standby unit. If the Standby unit has failed, updating takes place as soon as the Standby unit is brought back into operation.
Refer to Chapter 3, "Advanced Configurations," in the configuration guide for your respective software version referenced in the section, "Related Documentation" in "About This Manual."
Should you need to test the cable you received, the pinouts are shown in Figure 3-5.

This section contains some frequently asked questions about the failover feature.
Refer to the "Failover" section in Chapter 3, "Advanced Configurations," in the configuration guide for your respective software version referenced in the section, "Related Documentation" in "About This Manual."
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Posted: Fri Jun 2 09:48:58 PDT 2000
Copyright 1989 - 2000©Cisco Systems Inc.