<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX Failover - IP reachability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771890#M986233</link>
    <description>&lt;P&gt;In a typical Active/standby failover scenario, is it complulsory to have an IP reachability between a pair of interfaces ? For e.g DMZ interface on Primary is 192.168.55.1/24 and on secondary is 192.168.55.2/24. Can failover work normally if there is no connectivity between 192.168.55.1 and 192.168.55.1 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the 4 tests i.e.&lt;/P&gt;&lt;P&gt;1. Link Up/Down test&lt;/P&gt;&lt;P&gt;2. Network Activity test&lt;/P&gt;&lt;P&gt;3. ARP test&lt;/P&gt;&lt;P&gt;4. Broadcast Ping test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can be passed without reachablity between the interface pairs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Can somebody explain this and correct me on this?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:34:21 GMT</pubDate>
    <dc:creator>swapnendum</dc:creator>
    <dc:date>2019-03-11T10:34:21Z</dc:date>
    <item>
      <title>PIX Failover - IP reachability</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771890#M986233</link>
      <description>&lt;P&gt;In a typical Active/standby failover scenario, is it complulsory to have an IP reachability between a pair of interfaces ? For e.g DMZ interface on Primary is 192.168.55.1/24 and on secondary is 192.168.55.2/24. Can failover work normally if there is no connectivity between 192.168.55.1 and 192.168.55.1 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the 4 tests i.e.&lt;/P&gt;&lt;P&gt;1. Link Up/Down test&lt;/P&gt;&lt;P&gt;2. Network Activity test&lt;/P&gt;&lt;P&gt;3. ARP test&lt;/P&gt;&lt;P&gt;4. Broadcast Ping test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can be passed without reachablity between the interface pairs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Can somebody explain this and correct me on this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:34:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771890#M986233</guid>
      <dc:creator>swapnendum</dc:creator>
      <dc:date>2019-03-11T10:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Failover - IP reachability</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771891#M986234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No it cannot work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each of your failover cluster member sends "probes" to his mate on each monitored interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it cannot join the other one, it becomes active then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gaetan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2007 09:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771891#M986234</guid>
      <dc:creator>gaetan.allart</dc:creator>
      <dc:date>2007-06-25T09:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Failover - IP reachability</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771892#M986235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi  .. if the status of the interface (either from layer 1 to layer 3) is not OK, then the failver is triggered. If you are tying not to monitor one interface then you can do that by adding the  no monitor-interface if_name command from global config mode. Failover will work as normal but will not check the status of the interface where you entered the mentioned command.  by the way the command is on code 7.0 and above&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it help  ..  please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2007 10:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ip-reachability/m-p/771892#M986235</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2007-06-25T10:55:07Z</dc:date>
    </item>
  </channel>
</rss>

