
11-20
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Configuring Failover
To configure the secondary unit, perform the following steps:
Step 1 (PIX security appliance platform only) Enable LAN-based failover.
hostname(config)# failover lan enable
Step 2 Define the failover interface. Use the same settings as you used for the primary unit.
a. Specify the interface to be used as the failover interface.
hostname(config)# failover lan interface
if_name
phy_if
The if_name argument assigns a name to the interface specified by the phy_if argument.
b. Assign the active and standby IP address to the failover link.
hostname(config)# failover interface ip
if_name ip_addr mask
standby
ip_addr
Note Enter this command exactly as you entered it on the primary unit when you configured the
failover interface on the primary unit.
c. Enable the interface.
hostname(config)# interface
phy_if
hostname(config-if)# no shutdown
Step 3 (Optional) Designate this unit as the secondary unit.
hostname(config)# failover lan unit secondary
Note This step is optional because by default units are designated as secondary unless previously
configured.
Step 4 Enable failover.
hostname(config)# failover
After you enable failover, the active unit sends the configuration in running memory to the standby unit.
As the configuration synchronizes, the messages “Beginning configuration replication: Sending to mate”
and “End Configuration Replication to mate” appear on the active unit console.
Step 5 After the running configuration has completed replication, save the configuration to Flash memory.
hostname(config)# copy running-config startup-config
Configuring Optional Active/Standby Failover Settings
You can configure the following optional Active/Standby failover setting when you are initially
configuring failover or after failover has already been configured. Unless otherwise noted, the
commands should be entered on the active unit.
Komentarze do niniejszej Instrukcji