<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 7.0 failover issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466124#M533572</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;weird,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you don't have:&lt;/P&gt;&lt;P&gt;(config)#context &lt;NAME&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;configured anywhere either?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So all you did was add:&lt;/P&gt;&lt;P&gt;(config-if)#ip address active_addr netmask standby standby_addr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume you are using stateful failover?  You don't have an IP or name configued on the state-link interface right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Sep 2005 19:13:08 GMT</pubDate>
    <dc:creator>Steven Bourque</dc:creator>
    <dc:date>2005-09-06T19:13:08Z</dc:date>
    <item>
      <title>Pix 7.0 failover issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466121#M533569</link>
      <description>&lt;P&gt;Upgraded 6.3 to 7.0 on 515E, purchased FO license for another PIX 515E.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason the Primary PIX wants active/active failover.  I have not configured any contexts in the config, i assume it is on by default?  This wont work with FO license, from what i have read- no biggie, but how do i change the active/active to active/standby...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a working config on the fw and everything else works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASDM is about as much junk as the PDM- and it works whenever it desires... thought may be something in there?  I cant find anything in CLI to change it- do i have to change it to multiple mode, and then switch it back to single?  Is it license related- doubt it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another FW, FO group setup running 6.3 and had no problems setting it up...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideas&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466121#M533569</guid>
      <dc:creator>bklawson</dc:creator>
      <dc:date>2020-02-21T08:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.0 failover issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466122#M533570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct FO license does not support active/active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should look at:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008045247e.html#wp1058096" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008045247e.html#wp1058096&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It shows how to configure active/standby on PIX ver 7.0 for both failover and LAN Based failover.  (it also shows active/active which you seem to have configured)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pretty much it looks like for active/standby you don't use failover groups...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've never used PDM or ASDM.. so no help there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 18:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466122#M533570</guid>
      <dc:creator>Steven Bourque</dc:creator>
      <dc:date>2005-09-06T18:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.0 failover issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466123#M533571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed- been there, but i have not configured any groups - all that was done was added a standby IP for the interfaces, attached the cisco FO cable,   &lt;/P&gt;&lt;P&gt;and enabled failover...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is why I am confused- the FW is set as single mode, I have tried to force it to single mode- but it states this is the same mode it is using...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connection on the FO cable for the secondary has "failed"- I am assuming this is correct due to the A/A issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose i could rebuild the failover, but any ideas on why it is using A/A vs A/S... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 18:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466123#M533571</guid>
      <dc:creator>bklawson</dc:creator>
      <dc:date>2005-09-06T18:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.0 failover issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466124#M533572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;weird,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you don't have:&lt;/P&gt;&lt;P&gt;(config)#context &lt;NAME&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;configured anywhere either?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So all you did was add:&lt;/P&gt;&lt;P&gt;(config-if)#ip address active_addr netmask standby standby_addr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume you are using stateful failover?  You don't have an IP or name configued on the state-link interface right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 19:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466124#M533572</guid>
      <dc:creator>Steven Bourque</dc:creator>
      <dc:date>2005-09-06T19:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.0 failover issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466125#M533573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NOPE- unrecognizable command: for &lt;/P&gt;&lt;P&gt;(config)#context ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 19:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466125#M533573</guid>
      <dc:creator>bklawson</dc:creator>
      <dc:date>2005-09-06T19:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.0 failover issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466126#M533574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK- figured it out.  First even my rep didnt realize this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i rebooted my FO pix, i noticed a boot error stating a 3DES mismatch.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Mate's License (VPN-3DES-AES Enabled) is not compatible with my      &lt;/P&gt;&lt;P&gt;license (VPN-3DES-AES Disabled)  Failover will be disabled..." &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, i installed a new license for FO w/ 3DES and it took off, and is active/standby as expected.  I guess the A/A is default, until it is negotiated...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Learn something everyday in this Biz...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2005 21:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-issue/m-p/466126#M533574</guid>
      <dc:creator>bklawson</dc:creator>
      <dc:date>2005-09-06T21:00:28Z</dc:date>
    </item>
  </channel>
</rss>

