<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 515E FailOver Problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776979#M1005133</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 515E FO and it is st the factory defaults.  I simply assigned an IP Address to the inside interface.  I am trying to upgrade to 7.0, then 7.1(1), which is the version my UR is on.  I can't even ping any host on the same subnet, I am totally lost as to why this is happening?  I have the correct subnet mask and ip address scheme, yet i get no responses from any host i try to ping.  I have tried hooking up a cross over to a laptop and even that is unsuccessful.  I thought that maybe I had a defective unit so I RMA'd it, but the new unit is displaying the same behavior.  I am a afraid that I am missing something simple?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my show run:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf2 security4&lt;/P&gt;&lt;P&gt;nameif ethernet3 intf3 security6&lt;/P&gt;&lt;P&gt;nameif ethernet4 intf4 security8&lt;/P&gt;&lt;P&gt;nameif ethernet5 intf5 security10&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060carrier, 0 no carrier &lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;mtu intf3 1500&lt;/P&gt;&lt;P&gt;mtu intf4 1500&lt;/P&gt;&lt;P&gt;mtu intf5 1500&lt;/P&gt;&lt;P&gt;no ip address outside&lt;/P&gt;&lt;P&gt;ip address inside 10.18.1.18 255.255.0.0&lt;/P&gt;&lt;P&gt;no ip address intf2&lt;/P&gt;&lt;P&gt;no ip address intf3&lt;/P&gt;&lt;P&gt;no ip address intf4&lt;/P&gt;&lt;P&gt;no ip address intf5&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;o failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;no failover ip address intf2&lt;/P&gt;&lt;P&gt;no failover ip address intf3&lt;/P&gt;&lt;P&gt;no failover ip address intf4&lt;/P&gt;&lt;P&gt;no failover ip address intf5&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;pixfirewall(config)# ping 10.18.0.1&lt;/P&gt;&lt;P&gt;        10.18.0.1 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        10.18.0.1 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        10.18.0.1 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;pixfirewall(config)#&lt;/P&gt;&lt;P&gt;pixfirewall(config)# show int e1&lt;/P&gt;&lt;P&gt;interface ethernet1 "inside" is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82559 ethernet, address is 000a.b7bc.4bdb&lt;/P&gt;&lt;P&gt;  IP address 10.18.1.18, subnet mask 255.255.0.0&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;        1626 packets input, 155696 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;        Received 1632 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 packets output, 0 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (128/128) software (0/1)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (0/0) software (0/0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has a Failover Only (FO) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:10:47 GMT</pubDate>
    <dc:creator>DanielO</dc:creator>
    <dc:date>2019-03-11T10:10:47Z</dc:date>
    <item>
      <title>515E FailOver Problems</title>
      <link>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776979#M1005133</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 515E FO and it is st the factory defaults.  I simply assigned an IP Address to the inside interface.  I am trying to upgrade to 7.0, then 7.1(1), which is the version my UR is on.  I can't even ping any host on the same subnet, I am totally lost as to why this is happening?  I have the correct subnet mask and ip address scheme, yet i get no responses from any host i try to ping.  I have tried hooking up a cross over to a laptop and even that is unsuccessful.  I thought that maybe I had a defective unit so I RMA'd it, but the new unit is displaying the same behavior.  I am a afraid that I am missing something simple?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my show run:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf2 security4&lt;/P&gt;&lt;P&gt;nameif ethernet3 intf3 security6&lt;/P&gt;&lt;P&gt;nameif ethernet4 intf4 security8&lt;/P&gt;&lt;P&gt;nameif ethernet5 intf5 security10&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060carrier, 0 no carrier &lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;mtu intf3 1500&lt;/P&gt;&lt;P&gt;mtu intf4 1500&lt;/P&gt;&lt;P&gt;mtu intf5 1500&lt;/P&gt;&lt;P&gt;no ip address outside&lt;/P&gt;&lt;P&gt;ip address inside 10.18.1.18 255.255.0.0&lt;/P&gt;&lt;P&gt;no ip address intf2&lt;/P&gt;&lt;P&gt;no ip address intf3&lt;/P&gt;&lt;P&gt;no ip address intf4&lt;/P&gt;&lt;P&gt;no ip address intf5&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;o failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;no failover ip address intf2&lt;/P&gt;&lt;P&gt;no failover ip address intf3&lt;/P&gt;&lt;P&gt;no failover ip address intf4&lt;/P&gt;&lt;P&gt;no failover ip address intf5&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;pixfirewall(config)# ping 10.18.0.1&lt;/P&gt;&lt;P&gt;        10.18.0.1 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        10.18.0.1 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        10.18.0.1 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;pixfirewall(config)#&lt;/P&gt;&lt;P&gt;pixfirewall(config)# show int e1&lt;/P&gt;&lt;P&gt;interface ethernet1 "inside" is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82559 ethernet, address is 000a.b7bc.4bdb&lt;/P&gt;&lt;P&gt;  IP address 10.18.1.18, subnet mask 255.255.0.0&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;        1626 packets input, 155696 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;        Received 1632 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        0 packets output, 0 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (128/128) software (0/1)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (0/0) software (0/0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has a Failover Only (FO) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776979#M1005133</guid>
      <dc:creator>DanielO</dc:creator>
      <dc:date>2019-03-11T10:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: 515E FailOver Problems</title>
      <link>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776980#M1005134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue here is the FO license. A PIX with FO license cannot work in standalone mode. This is the reason why you cant ping its interfaces or ping hosts from this PIX. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may try enabling failover on PIX and then try doing upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address inside 10.18.1.18 255.255.0.0 &lt;/P&gt;&lt;P&gt;failover ip address inside 10.18.1.19&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wait for few secs, now this PIX should assume "Active" role and you should be able to ping the interface. Now try the upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2007 19:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776980#M1005134</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-05-08T19:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: 515E FailOver Problems</title>
      <link>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776981#M1005135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks so much, this was perfect.  I appreciate your assistance greatly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 15:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/515e-failover-problems/m-p/776981#M1005135</guid>
      <dc:creator>DanielO</dc:creator>
      <dc:date>2007-05-10T15:36:55Z</dc:date>
    </item>
  </channel>
</rss>

