<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 7.0 Failover Question/Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483007#M556997</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I belive you should be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This failover install was a brand new PIX deployment, so I dont things 7.0 was the cause. I bet it would have done the same thing on 6.3. I belive its an issue with the route table thats causing the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Jun 2005 17:34:10 GMT</pubDate>
    <dc:creator>joemarr_brodart</dc:creator>
    <dc:date>2005-06-20T17:34:10Z</dc:date>
    <item>
      <title>PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483001#M556990</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 questions, one of them may be more of a problem then a question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I be able to telnet secondary/standby unit via its assigned IP? My active unit is x.x.x.2 and the standby is x.x.x.3. I cant ping or telnet x.x.x.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2.&lt;/P&gt;&lt;P&gt;With a Active/Standby Cable-based w/ Stateful LAN, what is the expected time frame for failover to complete. When I manually failover the active to the standby it take between 45 to 60 seconds. I also noticed the adjacent routers show it looses OSPF neighbor status with the firewall during this time. Ill add the failover portions of my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.x.x 255.255.255.240 standby x.x.x.x &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.10.1 255.255.255.0 standby 192.168.10.3 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet2&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full  &lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet2.56&lt;/P&gt;&lt;P&gt; vlan 56&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 10.101.0.1 255.255.255.0 standby 10.101.0.11 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet3&lt;/P&gt;&lt;P&gt; description STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover polltime unit 1 holdtime 3&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link state Ethernet3&lt;/P&gt;&lt;P&gt;failover interface ip state 10.50.1.33 255.255.255.252 standby 10.50.1.34&lt;/P&gt;&lt;P&gt;monitor-interface outside&lt;/P&gt;&lt;P&gt;monitor-interface inside&lt;/P&gt;&lt;P&gt;monitor-interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483001#M556990</guid>
      <dc:creator>joemarr_brodart</dc:creator>
      <dc:date>2020-02-21T08:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483002#M556992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;For your first question, yes you should be able to ping and also to telnet to the secondary firewall. I have not test whether it will function like the primary if i actually redirect some of my traffic to it though....  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your second question, yes it does take quite a resonable amound of time to failover. In my opinion, other brands of firewalls does this better. ;)... and for the OSPF, that is something i really hope Cisco will indeed fix as i'm having the same problem. You can see why the OSPF has to rebuild it's neighborship by doing a "show failove". From there you will see what state or table is replicated/sync over to the failover unit. As you can see, there isn't any on OSPF neighbor state or OSPF database thus everything has to be rebuild from scratch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that helps.. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 07:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483002#M556992</guid>
      <dc:creator>lenny.lim</dc:creator>
      <dc:date>2005-06-20T07:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483003#M556993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. I dont thing it will handle traffic, while its in standby but I had thought I should have been able to telnet or ping it. Any thoughts on where to begin troubleshooting such an issue? Im also wondering now if maybe its related to the OSPF issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 08:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483003#M556993</guid>
      <dc:creator>joemarr_brodart</dc:creator>
      <dc:date>2005-06-20T08:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483004#M556994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps you should verify if the command "telnet 0 0 inside" is there and ping from a directly connected interface to the pix. If you still cannot, how about switching failover and test again.....  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 10:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483004#M556994</guid>
      <dc:creator>lenny.lim</dc:creator>
      <dc:date>2005-06-20T10:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483005#M556995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope it is not too late to jump in to this thread. I've got a 515E failover pair running 6.3(1), and the failover is very quick - most users don't even notice. I just received my RAM upgrade today and am planning to upgrade  to software version 7 this weekend. Are you saying that the failover time increases significantly? That would not be progress. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 14:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483005#M556995</guid>
      <dc:creator>mschomburg</dc:creator>
      <dc:date>2005-06-20T14:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483006#M556996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can telnet and ping from any directly connected device which leads me to believe its the lack of a routing table thats the problem. I rely on OSPF for my default also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 17:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483006#M556996</guid>
      <dc:creator>joemarr_brodart</dc:creator>
      <dc:date>2005-06-20T17:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483007#M556997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I belive you should be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This failover install was a brand new PIX deployment, so I dont things 7.0 was the cause. I bet it would have done the same thing on 6.3. I belive its an issue with the route table thats causing the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 17:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483007#M556997</guid>
      <dc:creator>joemarr_brodart</dc:creator>
      <dc:date>2005-06-20T17:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483008#M556998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;  The ver7.0 has some improvement in terms of failover. Especially on the power failure of the primary unit. When talking about failover, i recommend 7.0. It also now supports IPsec failover. &lt;/P&gt;&lt;P&gt; I got my unit with 6.3.4 and have upgraded it to 7.0. i've also just tested the failover with traffic passing through multiple subinterfaces (vlans) and the sessions stays. Though when i first configured i had a problem with both the unit as stands idle in the sync state. But after a cold reboot for both unit, seems to work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2005 11:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483008#M556998</guid>
      <dc:creator>lenny.lim</dc:creator>
      <dc:date>2005-06-21T11:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483009#M556999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is your your telnet command configured correctly or your access-list perhaps ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or like what you say, it's a routing problem. so does your return traffic know where to go ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2005 11:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483009#M556999</guid>
      <dc:creator>lenny.lim</dc:creator>
      <dc:date>2005-06-21T11:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 Failover Question/Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483010#M557000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I added a low  metric default as well as a route to my internals and I can now ping and telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2005 11:32:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-failover-question-problem/m-p/483010#M557000</guid>
      <dc:creator>joemarr_brodart</dc:creator>
      <dc:date>2005-06-21T11:32:57Z</dc:date>
    </item>
  </channel>
</rss>

