<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover on Pix 515-E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772080#M1008505</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand! &lt;/P&gt;&lt;P&gt;I never take care of a line in the sho failover :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;/P&gt;&lt;P&gt;        Link : Failover Ethernet2 (up)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact I only read this where is N/A !:&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: N/A - Serial-based failover enabled&lt;/P&gt;&lt;P&gt;Unit Poll frequency 15 seconds, holdtime 45 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot. It's good for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FFF# sho run | grep fail&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link Failover Ethernet2&lt;/P&gt;&lt;P&gt;failover interface ip Failover X.X.X.X 255.255.255.0 standby Y.Y.Y.Y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# sho fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: N/A - Serial-based failover enabled&lt;/P&gt;&lt;P&gt;Unit Poll frequency 15 seconds, holdtime 45 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 5 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 7.2(1), Mate 7.2(1)&lt;/P&gt;&lt;P&gt;Last Failover at: 15:08:30 UTC Apr 2 2007&lt;/P&gt;&lt;P&gt;        This host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 1650 (sec)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;/P&gt;&lt;P&gt;        Link : Failover Ethernet2 (up)&lt;/P&gt;&lt;P&gt;        Stateful Obj    xmit       xerr    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to disconnect the ethernet cable and the stateful go to Failed!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK..&lt;/P&gt;&lt;P&gt;Good. Thank you guys..  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Apr 2007 12:44:04 GMT</pubDate>
    <dc:creator>fargier</dc:creator>
    <dc:date>2007-04-02T12:44:04Z</dc:date>
    <item>
      <title>Failover on Pix 515-E</title>
      <link>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772078#M1008503</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A question again !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two PIX 515-E, one with UR licence and the other with FO licence only. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both serial cable (not really serial but you understand me) and ethernet cable are connected for the failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why?? Both are near. When I do a sho faiover i see that ethernet is : N/A. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The guy who configured before me this device said me that it was cisco who told him to make this confiugration with both cable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain me why? To maintain session??? I belived that it's only when you use serial cable that your session is saved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you a lot for your answer.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:54:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772078#M1008503</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2019-03-11T09:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Failover on Pix 515-E</title>
      <link>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772079#M1008504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two parts to failover.  One is required, the other is optional.  Let me explain:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Serial vs. LAN failover (required)&lt;/P&gt;&lt;P&gt;2) Stateful failover (optional)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For #1, you must choose to use the serial cable or an ethernet interface to send the failover configuration information to the peer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For #2, you can optionally enable stateful failover (which is an ethernet interface only) and this replicate the state of the connections/xlates/etc  from the Active to the Standby (high recommended so that failovers do not have any impact on users).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your PIXes are close by, I would suggest using Serial failover along with stateful failover (for state replication).  This may be what you have configured.  If you want to send the output of :&lt;/P&gt;&lt;P&gt;  show run | inc failover&lt;/P&gt;&lt;P&gt;  show failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can have a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 12:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772079#M1008504</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-04-02T12:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Failover on Pix 515-E</title>
      <link>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772080#M1008505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand! &lt;/P&gt;&lt;P&gt;I never take care of a line in the sho failover :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;/P&gt;&lt;P&gt;        Link : Failover Ethernet2 (up)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact I only read this where is N/A !:&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: N/A - Serial-based failover enabled&lt;/P&gt;&lt;P&gt;Unit Poll frequency 15 seconds, holdtime 45 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot. It's good for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FFF# sho run | grep fail&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link Failover Ethernet2&lt;/P&gt;&lt;P&gt;failover interface ip Failover X.X.X.X 255.255.255.0 standby Y.Y.Y.Y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# sho fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: N/A - Serial-based failover enabled&lt;/P&gt;&lt;P&gt;Unit Poll frequency 15 seconds, holdtime 45 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 5 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 7.2(1), Mate 7.2(1)&lt;/P&gt;&lt;P&gt;Last Failover at: 15:08:30 UTC Apr 2 2007&lt;/P&gt;&lt;P&gt;        This host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 1650 (sec)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;/P&gt;&lt;P&gt;        Link : Failover Ethernet2 (up)&lt;/P&gt;&lt;P&gt;        Stateful Obj    xmit       xerr    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to disconnect the ethernet cable and the stateful go to Failed!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK..&lt;/P&gt;&lt;P&gt;Good. Thank you guys..  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 12:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772080#M1008505</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2007-04-02T12:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Failover on Pix 515-E</title>
      <link>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772081#M1008506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi fargier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple of comments:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the "show failover" output, you have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#######&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: N/A - Serial-based &lt;/P&gt;&lt;P&gt;#######&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the "Cable status" is Normal, this means Serial failover is being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the "Failover LAN Interface" (for LAN based failover) indicates N/A, because it tells you "Serial-based" failover is used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config line "failover link Failover Ethernet2" indicates you are doing Stateful failover as well (as you noticied). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing I would suggest is to disable the http replication, by removing the line:&lt;/P&gt;&lt;P&gt;  failover replication http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This tells the PIX to replicate http connections (TCP/80) which it does not do by default.  The reason is, HTTP connections are very short lived, and the overhead of replicating all this connections is high.  So, unless you really need to replicate the HTTP connections, I would suggest against it.  Some reasons to do it is if you have HTTP connections that are long-lived, or if you are tunneling another application over HTTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2007 15:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failover-on-pix-515-e/m-p/772081#M1008506</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-04-02T15:51:35Z</dc:date>
    </item>
  </channel>
</rss>

