<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix sync connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108345#M894863</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pair of Pix's configured for failover and stateful sync, but i have discovered that the sync is not working, after some investigation it looks like one of the FW's has had its interface assigned to the wrong VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the fix is to assign the interface into the correct vlan, I wanted to know if there was any potential serivce impact when this happens, ie when the sync gets connected and starts working ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any thoughts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:59:32 GMT</pubDate>
    <dc:creator>stuart.jones</dc:creator>
    <dc:date>2019-03-11T13:59:32Z</dc:date>
    <item>
      <title>Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108345#M894863</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pair of Pix's configured for failover and stateful sync, but i have discovered that the sync is not working, after some investigation it looks like one of the FW's has had its interface assigned to the wrong VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the fix is to assign the interface into the correct vlan, I wanted to know if there was any potential serivce impact when this happens, ie when the sync gets connected and starts working ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any thoughts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:59:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108345#M894863</guid>
      <dc:creator>stuart.jones</dc:creator>
      <dc:date>2019-03-11T13:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108346#M894864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggets you posting the output of 'show failover'to be sure ..  however by the sound of it, you should not have any major issues. At the moment the current Active firewall must be forwarding packets and also monitoring the status of the standby firewall's interfaces. Once the status is normal, the failover relation will be completed and the configuration will be 'pushed' from Active to Standby. It is unlikely that traffic flow will be affected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts  !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 02:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108346#M894864</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-10-20T02:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108347#M894866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just make sure you take a backup of the configuration. Sometimes both units think they are active and it can erase the configuration on the desired primary unit. An easy way to make sure this does not happen is to 'ping' the other units failover interface before enabling 'failover' on both sides. And also making sure you have the correct boxes assigned as primary/secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 06:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108347#M894866</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-20T06:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108348#M894868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the output of the 'show failover' from both firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also was concerned if the IP address configured on the 'spare' interface on one of the units will cuase any issues even though the interface is shutdown ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Oct 2008 18:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108348#M894868</guid>
      <dc:creator>stuart.jones</dc:creator>
      <dc:date>2008-10-20T18:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108349#M894869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whichever interfaces you are not using you can disable failover monitoring for it using:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no monitor-interface &lt;NAME&gt; command.&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also it seems there is a communication problem on the stateful failover link. Can you ping both ends (active/stanby IPs)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2008 02:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108349#M894869</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-21T02:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108350#M894870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is the stateful link that is th elink which has been assigned to different vlans either end, and is the one i was intending to change to the correct vlan and was wondering if this would cause me the issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the ping, no i cannot ping either stateful interface from either FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2008 17:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108350#M894870</guid>
      <dc:creator>stuart.jones</dc:creator>
      <dc:date>2008-10-21T17:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Pix sync connection</title>
      <link>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108351#M894871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No this will hopefully cause no issues. Once you set both to the same VLAN the ping should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 06:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-sync-connection/m-p/1108351#M894871</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-22T06:32:36Z</dc:date>
    </item>
  </channel>
</rss>

