cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
569
Views
0
Helpful
3
Replies

PIX configuration Replication

fullerms
Level 1
Level 1

Hi all,

Is it possible to replciate the configuration of a PIX failover bundle across a wan link to another failover bundle? The idea is to set up two exits out of our network.

While traffic can be re-routed in case the primary gateway fails, our concern is to ensure the PIX ACLs and Nat configurations are available at the secondary at the time of failure.

We need a firewall at both gateways. How do we ensure that the configurations are replicated across both sites over the WAN? Changes will be made only at the primary site. The secondary site will be purely for backup only.

3 Replies 3

nkhawaja
Cisco Employee
Cisco Employee

you can try LAB based failover, and increase to failover timers to a high value.

I assume you mentioned LAN based failover.

Replication needs to happen between primary and secondary firewalls in the active site, AND then replicate to the failover bundle in the DR site.

Is this feasible, or do we need to place one firewall of the failover bundle in the active site and the other in the DR site?

yes i meant LAN based failover. But i thought that primary and secondary firewalls are in two separate sites. In your scenario, both primary and secondary on site1, and then you want the configs to be replicated to DR site, this is not possible via Failover.

You have to place one firewall of failover bundle in active site and other in the DR site, that is what i meant.

Thanks

Nadeem

Review Cisco Networking for a $25 gift card