<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix Failover Problem  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303280#M563417</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is a failover-only PIX, then it will exhibit the following after a power up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the &lt;B&gt;failover lan interface&lt;/B&gt; link status is up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The FO-only PIX will boot and automatically become active if it fails to detect the primary UR PIX.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The unit will reload itself every following 24 hours, automatically becoming active each time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the &lt;B&gt;failover lan interface&lt;/B&gt; link status is down:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The FO-only PIX will boot and come online but not become active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The command failover active must be manually executed to make the unit active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The unit will reload itself every following 24 hours, requiring another manual failover active to make it active each time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you hit the second condition, meaning the &lt;B&gt;failover lan interface&lt;/B&gt; status was down.  You would get this if you have a cross-over cable connected between the two PIX and the primary is still powered off or the cables were disconnected from it (which you said they were).  This is exactly why we suggest plugging all cables into a switch and not using cross-over cables, even if the primary is down the link status on the secondary will still be up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Aug 2004 01:07:37 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2004-08-03T01:07:37Z</dc:date>
    <item>
      <title>Pix Failover Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303279#M563416</link>
      <description>&lt;P&gt;I have two PIX's configured for lan-based failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other day there was a power failure, during which someone removed the lan cables from the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the power came back I expected the standby PIX to become active however I had to issue the failover active command before this happened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:32:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303279#M563416</guid>
      <dc:creator>m.reay</dc:creator>
      <dc:date>2020-02-21T07:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Failover Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303280#M563417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is a failover-only PIX, then it will exhibit the following after a power up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the &lt;B&gt;failover lan interface&lt;/B&gt; link status is up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The FO-only PIX will boot and automatically become active if it fails to detect the primary UR PIX.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The unit will reload itself every following 24 hours, automatically becoming active each time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the &lt;B&gt;failover lan interface&lt;/B&gt; link status is down:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The FO-only PIX will boot and come online but not become active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The command failover active must be manually executed to make the unit active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* The unit will reload itself every following 24 hours, requiring another manual failover active to make it active each time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you hit the second condition, meaning the &lt;B&gt;failover lan interface&lt;/B&gt; status was down.  You would get this if you have a cross-over cable connected between the two PIX and the primary is still powered off or the cables were disconnected from it (which you said they were).  This is exactly why we suggest plugging all cables into a switch and not using cross-over cables, even if the primary is down the link status on the secondary will still be up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2004 01:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303280#M563417</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-08-03T01:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Failover Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303281#M563418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply however all interfaces are connect to  a Cisco 4507R configured for multiple vlans, icluding a dedicated failover vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what the status  of the interface was, but can only assume that it was up as it was connected to a switch port - though I certainly wouldn't swear to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be due to the fact that spanning tree portfast wasnt configured on the port.   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2004 15:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303281#M563418</guid>
      <dc:creator>m.reay</dc:creator>
      <dc:date>2004-08-03T15:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Failover Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303282#M563419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Even with portfast disabled the link status should have been up if the port was up (even if it was in blocking state still).  Could the switch have been powered off or still coming up from the power outage?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would definately recommend enabling portfast on all the PIX-connected interfaces, this'll speed up failover enormously.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2004 23:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303282#M563419</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-08-03T23:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Pix Failover Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303283#M563420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No - the power came back on the sunday abd the problem was noticed on Monday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch was fully up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2004 06:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-problem/m-p/303283#M563420</guid>
      <dc:creator>m.reay</dc:creator>
      <dc:date>2004-08-04T06:01:39Z</dc:date>
    </item>
  </channel>
</rss>

