03-07-2011 11:50 AM - edited 03-11-2019 01:02 PM
I am looking to change my Failover Int IPs on my PIX 515E Bundle, Cisco PIX Firewall Version 6.3(5)123 with the least impact on the network.
For example:
interface ethernet5 "state"
IP address 172.18.0.245, subnet mask 255.255.255.252
ip address state 172.18.0.245 255.255.255.252
failover ip address state 172.18.0.246
I want to change these lines to .....
interface ethernet5 "state"
IP address 172.18.0.185, subnet mask 255.255.255.252
ip address state 172.18.0.185 255.255.255.252
failover ip address state 172.18.0.186
Thanks
03-07-2011 12:04 PM
You can make the change on the primary and then the secondary unit. IF your primary unit is active you can make the changes on the primary unit without failiing over. You will also need to make those changes on the secondary unit so that they can sync again.
In case you are worried about an outage you could try doing it off hours.
I hope this helps.
03-07-2011 12:30 PM
Thanks Paul, so I would not need to disable failover before making those changes on the Primary? Would it matter which lines I change first?
03-07-2011 12:35 PM
If you don't mind I would like to try on a lab. I don't remember well if you need to disable failover. Now that you mentioned it I think you have to. It's being a while.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide