<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 525 failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020613#M941307</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;active/active is when you have multiple contexts configured.  if you have multiple contexts configured, you can't use VPN's.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you dont need any other special licenses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Mar 2008 18:47:23 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2008-03-11T18:47:23Z</dc:date>
    <item>
      <title>PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020599#M941288</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 525s and they are doing failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my first affair with pix failovers so I want to know if I can get the running config of the stand-by PIX from the active one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020599#M941288</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2019-03-11T12:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020600#M941289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can simply telnet to the standby unit and do "show run" if you do not know the ip of standby,  issue on primary pix &lt;B&gt;show failover&lt;/B&gt; you will get output on standby ip.. also show failover will tell failover status,  if ok,  then your standby running config should be identical as primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 02:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020600#M941289</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-03-10T02:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020601#M941290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is my problem as every time I do "sh failover", this is what I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX525#sh failover&lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Cable status: Normal&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: N/A - Serial-based failover enabled&lt;/P&gt;&lt;P&gt;Unit Poll frequency 15 seconds, holdtime 45 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 2 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 7.2(2), Mate 7.2(2)&lt;/P&gt;&lt;P&gt;Last Failover at: 21:21:36 EST Mar 6 2008&lt;/P&gt;&lt;P&gt;        This host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 237825 (sec)&lt;/P&gt;&lt;P&gt;                  Interface outside (63.63.63.165): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface inside (192.168.252.2): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface intf2 (0.0.0.0): Link Down (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface intf3 (0.0.0.0): Link Down (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface intf4 (0.0.0.0): Link Down (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface intf5 (0.0.0.0): Link Down (Not-Monitored)&lt;/P&gt;&lt;P&gt;        Other host: Secondary - Standby Ready&lt;/P&gt;&lt;P&gt;                Active time: 690 (sec)&lt;/P&gt;&lt;P&gt;                  Interface outside (0.0.0.0): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface inside (0.0.0.0): Normal (Waiting)&lt;/P&gt;&lt;P&gt;                  Interface intf2 (0.0.0.0): Unknown (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface intf3 (0.0.0.0): Unknown (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface intf4 (0.0.0.0): Unknown (Not-Monitored)&lt;/P&gt;&lt;P&gt;                  Interface intf5 (0.0.0.0): Unknown (Not-Monitored)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stateful Failover Logical Update Statistics&lt;/P&gt;&lt;P&gt;        Link : Unconfigured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX525#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 02:29:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020601#M941290</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2008-03-10T02:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020602#M941291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please  to go over the physical connectivity on your standby unit with respect to outside interface and inside interface, does the standby pix inside connects to a switch and on same vlan just as the primary?, in other words, if you have two firewalls in failover each firewall interface connection to a switch for example must match the same vlan and actually be connected, the same goes for standby unit outside interface  connection to a switch..   if you have these connected to a switch , you can issue "failover reset " to restart failover, of course do it in non production hours., could you post config of failover portion from your primary pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094ea7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094ea7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 02:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020602#M941291</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-03-10T02:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020603#M941292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try consoling into the secondary unit and enter the command "failover".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 03:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020603#M941292</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-03-10T03:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020604#M941293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's my running config. I think failover is not configured or perhaps is not configured properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 11:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020604#M941293</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2008-03-10T11:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020605#M941294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Angel, go over this link to configure failover/standby configuration under code 7.x, I'll be on and off the forum, if you have any questions let us know. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 15:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020605#M941294</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-03-10T15:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020606#M941295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jorge, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for not getting back sooner... monday mornings.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now back at full speed on this project. It seems to me that this firewall is not setup for failover. Please confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, before I do go ahead and configure (with your help obviously &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ) this 525 for failover, I was doing some readings last night and found out that there are 2 types of failover: Active/Active failover and Active/Standby. (btw, that document is one of the documents I downloaded and read last night...) So, I want to ask you which is the best of them or which do you recommend?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Active/Active seduces me a bit as it also does load balancing, but again I am not too experienced on PIX failovers. I am just thinking "hey, if the secondary PIX will just be sitting there not doing any work, perhaps we'll give it some".... but again, I will follow the best and most recommended setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please advise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 16:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020606#M941295</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2008-03-10T16:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020607#M941296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, looking at your config output pix is not configured for failover , first you need to do is firewall licensese assesment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Primary " show version " output should tell you at the end  the type of failover lisence, e.i  FO  means Failover only , your standby show version output should be UR for unrestricted, FO and UR is Failover/Standby scenario,  I think if you have Active/Active then  you will see lisence differenlty, I will look it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make assesment of what type of cable failover is there from PIX1- to PIX2 to deternmined whether is lanbase failover etc.. since you cannot telnet to standby you will have to console to it to get show ver info etc.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime see &lt;B&gt;table 9&lt;/B&gt; for licensing info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/product_data_sheet09186a00800b0d85.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/product_data_sheet09186a00800b0d85.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you get assesment straight the link you read or the the one I provided in my second post gives example of standby/failover configuration .. I'll be more than happy to assist and Im very sure nepros will do as well.. I'll be off and on forum as Im a bit busy today.. but I'll try to lookup your model specs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2008 17:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020607#M941296</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-03-10T17:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020608#M941297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here it is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is from the only one I have access to. The other one I would have to go onsite and check it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this PIX meets the requirements&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 16:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020608#M941297</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2008-03-11T16:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020609#M941298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Angel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has an Unrestricted license and as such would be able to do failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 17:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020609#M941298</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-03-11T17:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020610#M941300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great..&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;and what about the line that says "Active/Active" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean this 525 can only do Active/Active failover? or can it also do the Active/Standby type of failover?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 17:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020610#M941300</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2008-03-11T17:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020611#M941303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it can do both.  most likely you'll want active/standby.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 18:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020611#M941303</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-03-11T18:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020612#M941305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome. Thanks for confirming this. Looks like I'm all set in this PIX. For the backup PIX, do I need any kind of special license as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And yes, I read that article, as well as the one for Active/Active and the Active/Standby looks like the route to go. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in which situations would you use Active/Active though? Distributing the load sounds like a good idea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 18:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020612#M941305</guid>
      <dc:creator>insccisco</dc:creator>
      <dc:date>2008-03-11T18:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 failover</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020613#M941307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;active/active is when you have multiple contexts configured.  if you have multiple contexts configured, you can't use VPN's.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you dont need any other special licenses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 18:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-failover/m-p/1020613#M941307</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-03-11T18:47:23Z</dc:date>
    </item>
  </channel>
</rss>

