
10-5
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Understanding Failover
The failover link can be one of the following connections:
• Serial failover cable (“cable-based failover”)—If the two units are within six feet of each other, then
we recommend that you use the serial failover cable. Using this cable allows the firewall to sense a
power loss of the peer unit, and to differentiate a power loss from an unplugged cable. The cable is
a modified RS-232 serial link cable that transfers data at 117,760 bps (115 Kbps). One end is labeled
“Primary” and attaches to the primary unit, while the other end is labeled “Secondary” and attaches
to the secondary unit. If you purchased a PIX Firewall failover bundle, this cable is included. To
order a spare, use part number PIX-FO.
• Ethernet connection (“LAN-based failover”)—You can use any unused Ethernet interface on the
device. If the units are further than six feet apart, use this method. We recommend that you connect
this link through a dedicated switch. You cannot use a crossover Ethernet cable to link the units
directly.
The disadvantages of using LAN-based failover include:
–
The PIX Firewall cannot immediately detect the loss of power of a peer, so the PIX Firewall
takes longer to fail over in this case.
–
You need to configure the failover link on the standby unit before it can communicate with the
active unit.
In cable-based failover, the standby unit can communicate directly with the active unit, and can
receive the entire configuration before enabling any interfaces or setting IP addresses.
–
The switch between the two units can be another point of hardware failure.
–
You have to dedicate an Ethernet interface (and switch ports) to the failover link, and the
interface cannot be used for regular traffic.
The benefits include:
–
Separation of the units by more than 6 feet.
–
Faster configuration replication.
State Link
For Stateful Failover, you must use an Ethernet link to pass state information. The PIX Firewall supports
the following Ethernet interface settings for the state link:
• Fast Ethernet (100BASE-T) full duplex
• Gigabit Ethernet (GE) (1000BASE-SX) full duplex
Note On a PIX 535 with GE interfaces, you must use a GE interface as the state link.
We recommend that you use a crossover cable to directly connect the units. You can also use a switch
between the units. No hosts or routers should be on this link.
If the two units are more than six feet apart, you can use the same Ethernet state link as the failover link,
but we recommend that you use a separate Ethernet link if available. If they are closer than 6 feet, we
recommend that you use the serial failover cable as the failover link.
Note If you use the same link for both state and failover, you cannot use a crossover cable.
Commentaires sur ces manuels