
11-16
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Configuring Failover
• Configuring LAN-Based Active/Standby Failover, page 11-17
• Configuring Optional Active/Standby Failover Settings, page 11-20
See the “Failover Configuration Examples” section on page 11-44 for examples of typical failover
configurations.
Prerequisites
Before you begin, verify the following:
• Both units have the same hardware, software configuration, and proper license.
• Both units are in the same mode (single or multiple, transparent or routed).
Configuring Cable-Based Active/Standby Failover (PIX Security Appliance Only)
Follow these steps to configure Active/Standby failover using a serial cable as the failover link. The
commands in this task are entered on the primary unit in the failover pair. The primary unit is the unit
that has the end of the cable labeled “Primary” plugged into it. For devices in multiple context mode, the
commands are entered in the system execution space unless otherwise noted.
You do not need to bootstrap the secondary unit in the failover pair when you use cable-based failover.
Leave the secondary unit powered off until instructed to power it on.
Cable-based failover is only available on the PIX security appliance platform.
To configure cable-based Active/Standby failover, perform the following steps:
Step 1 Connect the Failover cable to the PIX security appliances. Make sure that you attach the end of the cable
marked “Primary” to the unit you use as the primary unit, and that you attach the end of the cable marked
“Secondary” to the other unit.
Step 2 Power on the primary unit.
Step 3 If you have not done so already, configure the active and standby IP addresses for each interface (routed
mode) or for the management interface (transparent mode). The standby IP address is used on the
security appliance that is currently the standby unit. It must be in the same subnet as the active IP
address.
Note Do not configure an IP address for the state link if you are going to use Stateful Failover.
hostname(config-if)# ip address
active_addr netmask
standby
standby_addr
Note In multiple context mode, you must configure the interface addresses from within each context.
Use the changeto context command to switch between contexts. The command prompt changes
to hostname/
context
(config-if)#, where context is the name of the current context.
Step 4 (Optional) To enable Stateful Failover, configure the state link. The state link must be configured on an
unused interface.
a. Specify the interface to be used as the state link:
hostname(config)# failover link
if_name
phy_if
Commentaires sur ces manuels