<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pix failover transition time in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333831#M550427</link>
    <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I have configured my pix 525 for failover.&lt;/P&gt;&lt;P&gt;But when i power off my primary (active) unit the ping response initiated to a internet host from one of my vlan gets dropped for a minitue and i start getting the response only after a minute from the internet. &lt;/P&gt;&lt;P&gt;Is this transition period for failover the normal behaviour or it should come fast.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per cisco website i have read that standby unit should come up in 30 to 45 seconds &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output of the sh failover is pasted below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help appreciated&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parthiban&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh failover&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 3 seconds&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Last Failover at: xx:xx:xx xxx Thu Mar 10 2005&lt;/P&gt;&lt;P&gt; This host: Primary - Active&lt;/P&gt;&lt;P&gt; Active time: 598662 (sec)&lt;/P&gt;&lt;P&gt;Interface outside (x.x.x.x): Normal&lt;/P&gt;&lt;P&gt;Interface inside (10.1.253.1): Normal&lt;/P&gt;&lt;P&gt;Interface stateful-failover (10.1.252.1): Normal&lt;/P&gt;&lt;P&gt;Interface intf3 (0.0.0.0): Link Down (Shutdown)&lt;/P&gt;&lt;P&gt;Interface REMOTEZONE (10.1.7.254): Normal&lt;/P&gt;&lt;P&gt;Interface DMZ (10.1.14.254): Normal&lt;/P&gt;&lt;P&gt;Interface BACKBONEZONE (10.1.6.30): Normal&lt;/P&gt;&lt;P&gt;Interface INTF4 (0.0.0.0): Link Down (Shutdown)&lt;/P&gt;&lt;P&gt;Other host: Secondary - Standby&lt;/P&gt;&lt;P&gt;Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;Other host: Secondary - Standby&lt;/P&gt;&lt;P&gt;Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;Interface outside (x.x.x.x): Normal&lt;/P&gt;&lt;P&gt;Interface inside (10.1.253.2): Normal&lt;/P&gt;&lt;P&gt;Interface stateful-failover (10.1.252.2): Normal&lt;/P&gt;&lt;P&gt;Interface intf3 (0.0.0.0): Link Down (Shutdown)&lt;/P&gt;&lt;P&gt;Interface REMOTEZONE (10.1.7.253): Normal&lt;/P&gt;&lt;P&gt;Interface DMZ (10.1.14.253): Normal&lt;/P&gt;&lt;P&gt;Interface BACKBONEZONE (10.1.6.29): Normal&lt;/P&gt;&lt;P&gt;Interface INTF4 (10.1.6.28): Link Down (Shutdown)&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:01:16 GMT</pubDate>
    <dc:creator>ponparthi</dc:creator>
    <dc:date>2020-02-21T08:01:16Z</dc:date>
    <item>
      <title>pix failover transition time</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333831#M550427</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I have configured my pix 525 for failover.&lt;/P&gt;&lt;P&gt;But when i power off my primary (active) unit the ping response initiated to a internet host from one of my vlan gets dropped for a minitue and i start getting the response only after a minute from the internet. &lt;/P&gt;&lt;P&gt;Is this transition period for failover the normal behaviour or it should come fast.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per cisco website i have read that standby unit should come up in 30 to 45 seconds &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output of the sh failover is pasted below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help appreciated&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parthiban&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh failover&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 3 seconds&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Last Failover at: xx:xx:xx xxx Thu Mar 10 2005&lt;/P&gt;&lt;P&gt; This host: Primary - Active&lt;/P&gt;&lt;P&gt; Active time: 598662 (sec)&lt;/P&gt;&lt;P&gt;Interface outside (x.x.x.x): Normal&lt;/P&gt;&lt;P&gt;Interface inside (10.1.253.1): Normal&lt;/P&gt;&lt;P&gt;Interface stateful-failover (10.1.252.1): Normal&lt;/P&gt;&lt;P&gt;Interface intf3 (0.0.0.0): Link Down (Shutdown)&lt;/P&gt;&lt;P&gt;Interface REMOTEZONE (10.1.7.254): Normal&lt;/P&gt;&lt;P&gt;Interface DMZ (10.1.14.254): Normal&lt;/P&gt;&lt;P&gt;Interface BACKBONEZONE (10.1.6.30): Normal&lt;/P&gt;&lt;P&gt;Interface INTF4 (0.0.0.0): Link Down (Shutdown)&lt;/P&gt;&lt;P&gt;Other host: Secondary - Standby&lt;/P&gt;&lt;P&gt;Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;Other host: Secondary - Standby&lt;/P&gt;&lt;P&gt;Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;Interface outside (x.x.x.x): Normal&lt;/P&gt;&lt;P&gt;Interface inside (10.1.253.2): Normal&lt;/P&gt;&lt;P&gt;Interface stateful-failover (10.1.252.2): Normal&lt;/P&gt;&lt;P&gt;Interface intf3 (0.0.0.0): Link Down (Shutdown)&lt;/P&gt;&lt;P&gt;Interface REMOTEZONE (10.1.7.253): Normal&lt;/P&gt;&lt;P&gt;Interface DMZ (10.1.14.253): Normal&lt;/P&gt;&lt;P&gt;Interface BACKBONEZONE (10.1.6.29): Normal&lt;/P&gt;&lt;P&gt;Interface INTF4 (10.1.6.28): Link Down (Shutdown)&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333831#M550427</guid>
      <dc:creator>ponparthi</dc:creator>
      <dc:date>2020-02-21T08:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: pix failover transition time</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333832#M550429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have the failover poll interval to the minimum.. i think 3 secs is the min value.. another thing to make sure is to have the switch ports connected to the PIX firewall interfaces, to have port fast enabled...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Portfast should be enabled on all the ports whre the PIX interface directly connects, and trunking, channeling should be disabled.. this way, if the PIX's interface goes down during failover, the switch does not have to wait for 30 secs while the port is transitioned from listening state to a forwarding state....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try this and let us know....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2005 11:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333832#M550429</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-03-17T11:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: pix failover transition time</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333833#M550433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raj&lt;/P&gt;&lt;P&gt;Thanks for your response. I have enabled the post fast already for  all the ports directly connected to pix. but trunking is also off, I have given switchport mode access in all the ports. what do u mean by channeling on these ports.&lt;/P&gt;&lt;P&gt;Further my client is worried about the transition time of the secondary firewall only when primary (active) goes down. &lt;/P&gt;&lt;P&gt;So when i power down my primary active could you please tell me how fast the secondary will become active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parthiban&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Mar 2005 06:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-transition-time/m-p/333833#M550433</guid>
      <dc:creator>ponparthi</dc:creator>
      <dc:date>2005-03-18T06:22:08Z</dc:date>
    </item>
  </channel>
</rss>

