<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic standby on active/active failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407828#M742628</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt; I was reading this documentation &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;for doing active/active failover using pix 8.0. But I have the impresion that the concept of stanby used on pix firewall is not the same as this used on cisco router.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;i think that the command&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN style="font-weight: normal; font-style: italic;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ip address active_addr netmask standby standby_addr&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does not means that standby_addr will be use as the gateway for a network but the ip address of the stanby unit.&lt;/P&gt;&lt;P&gt;If i do this on the failover interface I dont see the point of doing if for every interface or subinterface the contexts&amp;nbsp; have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone explained that clearly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:16:44 GMT</pubDate>
    <dc:creator>roussillon</dc:creator>
    <dc:date>2019-03-11T17:16:44Z</dc:date>
    <item>
      <title>standby on active/active failover</title>
      <link>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407828#M742628</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt; I was reading this documentation &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;for doing active/active failover using pix 8.0. But I have the impresion that the concept of stanby used on pix firewall is not the same as this used on cisco router.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;i think that the command&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN style="font-weight: normal; font-style: italic;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ip address active_addr netmask standby standby_addr&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does not means that standby_addr will be use as the gateway for a network but the ip address of the stanby unit.&lt;/P&gt;&lt;P&gt;If i do this on the failover interface I dont see the point of doing if for every interface or subinterface the contexts&amp;nbsp; have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone explained that clearly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407828#M742628</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2019-03-11T17:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: standby on active/active failover</title>
      <link>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407829#M742647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Other fact if the context in active failover-group provides the configuration for the corresponding context in standby failover-group I do not see the reason of creating stanby ip address for each interface exept for those used as&amp;nbsp; failover interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please correcxt me if i am wrong!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 20:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407829#M742647</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2010-03-02T20:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: standby on active/active failover</title>
      <link>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407830#M742659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;roussillon wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt; I was reading this documentation &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080834058.shtml&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;for doing active/active failover using pix 8.0. But I have the impresion that the concept of stanby used on pix firewall is not the same as this used on cisco router.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;i think that the command&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN style="font-weight: normal; font-style: italic;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ip address active_addr netmask standby standby_addr&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;does not means that standby_addr will be use as the gateway for a network but the ip address of the stanby unit.&lt;/P&gt;
&lt;P&gt;If i do this on the failover interface I dont see the point of doing if for every interface or subinterface the contexts&amp;nbsp; have?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can someone explained that clearly?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct in that the standby address is never used as the gateway for the clients. It is used for 2 reasons -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) so you can connect to the standby firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) so the firewalls can monitor each others state on those interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need to configure every interface with a standby address if you don't want to and sometimes you don't if you are using public IP addressing on the interfaces. If you are using private addressing i can't see any reason why you wouldn't use a standby address to be honest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 20:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407830#M742659</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-03-02T20:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: standby on active/active failover</title>
      <link>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407831#M742676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read again the cisco documentation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and standby ip for each interface or subinterface(in case of vlans) is used for failover in context level&lt;/P&gt;&lt;P&gt;cited by cisco documentation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Failover is triggered at the failover group&amp;nbsp; level when one of these &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; events occurs:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Too many monitored interfaces in the group fail.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The &lt;STRONG&gt;no failover active group group_id&lt;/STRONG&gt; or &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;failover active group group_id&lt;/STRONG&gt; command is &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;entered.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of cause we have to monitor those interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 21:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/standby-on-active-active-failover/m-p/1407831#M742676</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2010-03-02T21:53:10Z</dc:date>
    </item>
  </channel>
</rss>

