
10-2
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Failover System Requirements
Failover System Requirements
Table 10-1 lists the system requirements for the failover feature.
Ta b l e 10-1 Failover System Requirements
Requirement Description
Supported PIX Firewall
models
• PIX 515
• PIX 515E
• PIX 520
• PIX 525
• PIX 535
Note The PIX 501 and PIX 506E models do not support failover.
Identical PIX Firewall
hardware and software
versions
The failover feature requires two units that are identical in the
following respects:
• Model (a PIX 515E cannot be used with a PIX 515)
• Same number and type of interfaces
• Software version
• Activation key type (DES or 3DES)
• Flash memory
• Amount of RAM
Note The PIX-4FE and PIX-4FE-66 cards are considered equivalent
and interchangeable. You can install a PIX-4FE in the primary
unit and a PIX-4FE-66 in the secondary unit, as long as you
install them in the same slot number of each chassis. For
example, if you install a PIX-4FE in Slot 1 of the primary unit,
the PIX-4FE-66 must be installed in Slot 1 of the secondary
unit.
At least one unit with an
Unrestricted (UR) license
The other unit can have a Failover Only (FO) or another UR license.
Units with a Restricted license cannot be used for failover, and two
units with FO licenses cannot be used together as a failover pair.
The PIX Firewall with the FO license is intended to be used solely for
failover and not in standalone mode. If a failover unit is used in
standalone mode, the unit will reboot at least once every 24 hours until
the unit is returned to failover duty. When the unit reboots, the
following message displays on the console:
=========================NOTICE=========================
This machine is running in secondary mode without
a connection to an active primary PIX. Please
check your connection to the primary system.
REBOOTING....
========================================================
Commentaires sur ces manuels