
11-50
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Failover Configuration Examples
security-level 100
ip address 192.168.0.1 255.255.255.0 standby 192.168.0.11
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname admin
pager lines 24
mtu outside 1500
mtu inside 1500
no vpn-addr-assign aaa
no vpn-addr-assign dhcp
no vpn-addr-assign local
monitor-interface outside
monitor-interface inside
no asdm history enable
arp timeout 14400
route outside 0.0.0.0 0.0.0.0 192.168.5.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00
h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp
fragment size 200 outside
fragment chain 24 outside
fragment timeout 5 outside
fragment size 200 inside
fragment chain 24 inside
fragment timeout 5 inside
telnet timeout 5
ssh timeout 5
console timeout 0
!
class-map inspection_default
match default-inspection-traffic
!
!
Example 11-6 The ctx1 Context Configuration
interface Ethernet3
nameif inside
security-level 100
ip address 192.168.20.1 255.255.255.0 standby 192.168.20.11
!
interface Ethernet4
nameif outside
security-level 0
ip address 192.168.10.31 255.255.255.0 standby 192.168.10.41
asr-group 1
!
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname ctx1
access-list 201 extended permit ip any any
pager lines 24
logging console informational
mtu inside 1500
mtu outside 1500
no vpn-addr-assign aaa
no vpn-addr-assign dhcp
no vpn-addr-assign local
Komentarze do niniejszej Instrukcji