11-12-2006 08:08 AM - edited 02-21-2020 01:18 AM
Hi,I have the following network architecture:
Core switch(A)6509==Core switch(B)6509
| |
PIX535(A)----------PIX535(B)
| |
Switch(A)3560==Switch(B)3560
| |
Border Router(A) Border Router(B)
| |
Extranet Network
Pls help me and give me any good advice for the architecture for fulfiling the full failover.
Thanks
11-17-2006 09:12 AM
PIX Firewall failover allows you to configure two PIX Firewall units in a fully redundant topology.
For configuring failover
12-01-2006 03:20 AM
I have put in a number of architectures based on a pair of PIX and a pair of 2960s. using the WS-C2960-24TT-L, link the two GE ports as channelled trunks. Create as many VLANs as you need, ensuring that each VLAN appears on both switches. Connect your core switches, one to each 2960 and your inside interfaces, again, one to each. Connect other interfaces in a similar fashion. This allows for the complete failure of any one device.
If you need to physically separate the devices, use the WS-C2960-24TC-L switches, and fibre SFPs, don't channel the uplinks, but use RSTP over two separate links, with the heartbeat and sync connections biased onto one link and the data connections biased onto the other.
Hope this helps.
Dave
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide