
11-23
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Configuring Failover
Configuring Active/Active Failover
This section describes how to configure Active/Active failover.
This section includes the following topics:
• Prerequisites, page 11-23
• Configuring Cable-Based Active/Active Failover (PIX security appliance Only), page 11-23
• Configuring LAN-Based Active/Active Failover, page 11-25
• Configuring Optional Active/Active Failover Settings, page 11-28
See the “Failover Configuration Examples” section on page 11-44 for examples of typical failover
configurations.
Prerequisites
Before you begin, verify the following:
• Both units have the same hardware, software configuration, and proper license.
• Both units are in multiple context mode.
Configuring Cable-Based Active/Active Failover (PIX security appliance Only)
Follow these steps to configure Active/Active failover using a serial cable as the failover link. The
commands in this task are entered on the primary unit in the failover pair. The primary unit is the unit
that has the end of the cable labeled “Primary” plugged into it. For devices in multiple context mode, the
commands are entered in the system execution space unless otherwise noted.
You do not need to bootstrap the secondary unit in the failover pair when you use cable-based failover.
Leave the secondary unit powered off until instructed to power it on.
Cable-based failover is only available on the PIX security appliance platform.
To configure cable-based, Active/Active failover, perform the following steps:
Step 1 Connect the failover cable to the PIX security appliances. Make sure that you attach the end of the cable
marked “Primary” to the unit you use as the primary unit, and that you attach the end of the cable marked
“Secondary” to the unit you use as the secondary unit.
Step 2 Power on the primary unit.
Step 3 If you have not done so already, configure the active and standby IP addresses for each interface (routed
mode) or for the management interface (transparent mode). The standby IP address is used on the
security appliance that is currently the standby unit. It must be in the same subnet as the active IP
address.
Note Do not configure an IP address for the state link if you are going to use Stateful Failover.
hostname(config-if)# ip address
active_addr netmask
standby
standby_addr
Komentarze do niniejszej Instrukcji