
10-23
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Frequently Asked Failover Questions
Configuration Replication Questions
• Does configuration replication save the configuration to Flash memory on the standby unit?
No, the configuration is only in running memory.
• How can both units be configured the same without manually entering the configuration twice?
Commands entered on the active unit are automatically replicated to the standby unit.
• What happens if I enter commands on the standby unit?
You will see an error message telling you that the configurations are out of sync.
If you enter individual commands on the active unit that are replicated to the standby unit, your
alterations are preserved.
If you use the write standby command on the active unit, it will erase any new commands you
entered on the standby unit.
• What happens if I enter the write memory command on the active unit?
The write memory command is replicated to the standby unit, which proceeds to write its
configuration to Flash memory.
• What happens if the configuration in Flash memory on the secondary unit differs from the
configuration on the primary unit?
After startup, the primary unit sends its configuration to the secondary unit, and erases the secondary
unit’s running configuration. However, the secondary unit’s configuration remains unaltered in
Flash memory.
• How can I view the running configuration and the Flash memory configuration?
–
show running—Shows the running configuration. You can also enter write terminal.
–
show config—Shows the configuration in Flash memory.
Basic Failover Questions
• Which unit becomes active if you restart both units?
The primary unit.
• What happens if the active unit has a power failure?
–
Cable-based—The standby unit learns immediately of the active power failure, and becomes
active.
–
LAN-based—After hello packets are not acknowledged, the standby unit becomes active. There
is a slight delay compared to cable-based failover.
• What happens when the formerly active unit comes online again?
No failover occurs. It remains in standby mode.
Commentaires sur ces manuels