<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 6.2 (failover to primary) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187185#M609087</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the command. but I have another problem. I have 2 pix firewalls, let's say 'F' and 'P'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ip address of F is f.f.f.f and the ip address of P is p.p.p.p.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I telnet into F and do config t , I get the following message:&lt;/P&gt;&lt;P&gt;Pix-Admin1# config t&lt;/P&gt;&lt;P&gt;**** WARNING ***&lt;/P&gt;&lt;P&gt;        Configuration Replication is NOT performed from Standby unit to Active u&lt;/P&gt;&lt;P&gt;nit.&lt;/P&gt;&lt;P&gt;        Configurations are no longer synchronized.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I telnet into P and do show failover I get&lt;/P&gt;&lt;P&gt;Pix-Admin1(config)# sh fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 15 seconds&lt;/P&gt;&lt;P&gt;        This host: Secondary - Active&lt;/P&gt;&lt;P&gt;                Active time: 375 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.1): Normal&lt;/P&gt;&lt;P&gt;                Interface none2 (2.2.2.2): Link Down (Shutdo&lt;/P&gt;&lt;P&gt;                Interface statefailover:5 (1.1.1.1): Link Do&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;        Other host: Primary - Standby&lt;/P&gt;&lt;P&gt;                Active time: 960 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.2): Normal&lt;/P&gt;&lt;P&gt;                Interface none2 (0.0.0.0): Link Down (Shutdo&lt;/P&gt;&lt;P&gt;                Interface statefailover:5 (0.0.0.0): Link Do&lt;/P&gt;&lt;P&gt;                &lt;/P&gt;&lt;P&gt;I did " no failover active" and made the primary active. but I cant do config t on F. why so? and how do I synchronize the 2 firewalls and get rid of the warning. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Feb 2003 20:33:40 GMT</pubDate>
    <dc:creator>vikrantarora</dc:creator>
    <dc:date>2003-02-21T20:33:40Z</dc:date>
    <item>
      <title>Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187183#M609082</link>
      <description>&lt;P&gt;I recently joined a company where PIX firewall is installed. but the active link on failover is red , i want to make the primary pix as active. how do i do it?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187183#M609082</guid>
      <dc:creator>vikrantarora</dc:creator>
      <dc:date>2020-02-21T06:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187184#M609084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use the 'failover active' command to initiate a failover switch from the standby unit (or the 'no failover active' command from the active unit to initiate a failover switch). You can use this feature to return a failed unit to service, or to force an active unit off line for maintenance. Because the standby unit does not keep state information on each connection, all active connections will be dropped and must be re-established by the clients.&lt;/P&gt;&lt;P&gt;Verify with 'show failover' to make sure who is active.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2003 18:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187184#M609084</guid>
      <dc:creator>steve.barlow</dc:creator>
      <dc:date>2003-02-21T18:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187185#M609087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the command. but I have another problem. I have 2 pix firewalls, let's say 'F' and 'P'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ip address of F is f.f.f.f and the ip address of P is p.p.p.p.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I telnet into F and do config t , I get the following message:&lt;/P&gt;&lt;P&gt;Pix-Admin1# config t&lt;/P&gt;&lt;P&gt;**** WARNING ***&lt;/P&gt;&lt;P&gt;        Configuration Replication is NOT performed from Standby unit to Active u&lt;/P&gt;&lt;P&gt;nit.&lt;/P&gt;&lt;P&gt;        Configurations are no longer synchronized.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I telnet into P and do show failover I get&lt;/P&gt;&lt;P&gt;Pix-Admin1(config)# sh fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 15 seconds&lt;/P&gt;&lt;P&gt;        This host: Secondary - Active&lt;/P&gt;&lt;P&gt;                Active time: 375 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.1): Normal&lt;/P&gt;&lt;P&gt;                Interface none2 (2.2.2.2): Link Down (Shutdo&lt;/P&gt;&lt;P&gt;                Interface statefailover:5 (1.1.1.1): Link Do&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;        Other host: Primary - Standby&lt;/P&gt;&lt;P&gt;                Active time: 960 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.2): Normal&lt;/P&gt;&lt;P&gt;                Interface none2 (0.0.0.0): Link Down (Shutdo&lt;/P&gt;&lt;P&gt;                Interface statefailover:5 (0.0.0.0): Link Do&lt;/P&gt;&lt;P&gt;                &lt;/P&gt;&lt;P&gt;I did " no failover active" and made the primary active. but I cant do config t on F. why so? and how do I synchronize the 2 firewalls and get rid of the warning. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2003 20:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187185#M609087</guid>
      <dc:creator>vikrantarora</dc:creator>
      <dc:date>2003-02-21T20:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187186#M609089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;F is your standby and P is your active.  You shouldn't enter config changes on your standy, only your active.  But your F is designated as your primary, so if you want to make it the active PIX again either enter the 'no failover active' command on the secondary unit (to switch service to the primary) or the 'failover active' command on the primary unit.  Ideally you want F to be primary and active, and P to be secondary and standby.  Then you will be in synch and won't see that error (if you make changes on F only, and when it is the primary active PIX).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2003 14:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187186#M609089</guid>
      <dc:creator>steve.barlow</dc:creator>
      <dc:date>2003-02-24T14:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187187#M609091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets start from the beginning, as i think there is some confusion in the terminology or understanding at my part:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telnet 192.xxx.xxx.190 i.e labelled 'Primary' and is active at the moment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix-Admin1(config)# sh fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 15 seconds &lt;/P&gt;&lt;P&gt;       This host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 237690 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.1): Normal&lt;/P&gt;&lt;P&gt;        Other host: Secondary - Standby&lt;/P&gt;&lt;P&gt;                Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.2): Normal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telnet 192.xxx.xxx.180 i.e labelled 'Failover' and is not active at the&lt;/P&gt;&lt;P&gt;moment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix-Admin1(config)# sh fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 15 seconds&lt;/P&gt;&lt;P&gt;        This host: Secondary - Standby&lt;/P&gt;&lt;P&gt;                Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.2): Normal            &lt;/P&gt;&lt;P&gt;        Other host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 237840 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.1): Normal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**********************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chnaging any config'n or doing 'config t' on 192.xxx.xxx.180 gives the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix-Admin1(config)#  config t&lt;/P&gt;&lt;P&gt;**** WARNING ***&lt;/P&gt;&lt;P&gt;        Configuration Replication is NOT performed from Standby unit to Active u&lt;/P&gt;&lt;P&gt;nit.&lt;/P&gt;&lt;P&gt;        Configurations are no longer synchronized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both consoles hang now!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I telnet again,  do a 'no failover active' at 192.xxx.xxx.190. Window closes after some time on its own.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*****************************&lt;/P&gt;&lt;P&gt;I telnet again into 192.xxx.xxx.190 and do 'sh fail' and get:&lt;/P&gt;&lt;P&gt;Pix-Admin1# sh fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 15 seconds&lt;/P&gt;&lt;P&gt;        This host: Secondary - Active&lt;/P&gt;&lt;P&gt;                Active time: 180 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.1): Normal&lt;/P&gt;&lt;P&gt;        Other host: Primary - Standby&lt;/P&gt;&lt;P&gt;                Active time: 238050 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.2): Normal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*********************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I telnet into 192.xxx.xxx.180 and do 'sh fail' and get:&lt;/P&gt;&lt;P&gt;Pix-Admin1# sh fail&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Reconnect timeout 0:00:00&lt;/P&gt;&lt;P&gt;Poll frequency 15 seconds&lt;/P&gt;&lt;P&gt;        This host: Primary - Standby&lt;/P&gt;&lt;P&gt;                Active time: 238050 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.2): Normal&lt;/P&gt;&lt;P&gt;        Other host: Secondary - Active&lt;/P&gt;&lt;P&gt;                Active time: 285 (sec)&lt;/P&gt;&lt;P&gt;                Interface statefailover (3.3.3.1): Normal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still, Chnaging any config'n or doing 'config t' on 192.xxx.xxx.180 gives the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix-Admin1#    config t&lt;/P&gt;&lt;P&gt;**** WARNING ***&lt;/P&gt;&lt;P&gt;        Configuration Replication is NOT performed from Standby unit to Active u&lt;/P&gt;&lt;P&gt;nit.&lt;/P&gt;&lt;P&gt;        Configurations are no longer synchronized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***************************&lt;/P&gt;&lt;P&gt; DOUBTS!&lt;/P&gt;&lt;P&gt;    &lt;/P&gt;&lt;P&gt;From my observation, 'THIS HOST' and 'OTHER HOST' chnage from primary to secondary and vice verca. So, we should not label one of the firewalls as 'Primary' and How do I make sure that primary is failover and active?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly, how do I rmeove the Warning I keep geeting on 192.xxx.xxx.180?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do we give no failover active on priamry and failover active active on &lt;/P&gt;&lt;P&gt;standby only? I my case I can not give any command on 192.xxx.xxx.180?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your help and patience!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2003 16:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187187#M609091</guid>
      <dc:creator>vikrantarora</dc:creator>
      <dc:date>2003-02-24T16:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187188#M609094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There seems to be some confusion with primary, secondary, active and standby.  In your scenario, it is which ever pix is 'active' that will always have the .190 address, whether it is the primary or secondary, and similarly, the 'standby' pix will always take the .180 address.  It is the 'active' pix you need to configure, not the 'standby', as the standby unit will not replicate changes to the active unit, and this is the error you are seeing.  You need to telnet to the 190 address in order to configure the pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2003 18:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187188#M609094</guid>
      <dc:creator>kagodfrey</dc:creator>
      <dc:date>2003-02-24T18:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 6.2 (failover to primary)</title>
      <link>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187189#M609095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for sharing that information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please dont reply if i am right in saying  that i can , under no circumstances , configure the .180 pix directly. it has to pick up configuration from primary which i can force by " wr standby" command on the .190 pix&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;vikrant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Feb 2003 18:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-6-2-failover-to-primary/m-p/187189#M609095</guid>
      <dc:creator>vikrantarora</dc:creator>
      <dc:date>2003-02-25T18:50:23Z</dc:date>
    </item>
  </channel>
</rss>

