cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
449
Views
0
Helpful
3
Replies

PIX failover mechanism

leejoansin
Level 1
Level 1

I am deploying a pair of PIX directly connecting to a pair of firewalls managed by a 3rd party. My firewall pair is to provide for the necessary redundancy in case of failure in the master PIX. The connections between PIX and 3rd party's firewalls were point-to-point, i.e. master PIX to master firewall and standby PIX to standby firewall (See Scenario 1). However I was told that connecting in this way will cause failover mechanism to fail. To make the failover works I have to connect as per in Scenario 2.

Qn:

1. Is it true that I need to connect in scenario 2?

2. Just wondering how the PIX failover mechanism works? Is it by keepalive messages sending across the external-facing interfaces?

Thank you!

3 Replies 3

Scenario two is the correct way. The reason being that the PIX firewalls in a failover configuration send failover hello packets on all interfaces and if an interface does not detect two consecutive hello packets in a specific time interval the interface enters testing mode.

Thank you! It helps a lot! :-)

Review Cisco Networking for a $25 gift card