Hi,
Can someone help with what the correct steps are for replacing a primary PIX firewall unit. Here are the steps I followed, but it did not quite go to plan:
Replacement of PIX Primary Unit:
1. I forced the standby to become active by issuing the "failover active" command on the standby firewall, before commencing work.
2. We installed the replacement unit, powered it up (of course at this stage it did not have any configuration).
3. Keeping the primary unit turned on, I then connected the failover serial cable and expected the the config to be copied from the current active unit (standby unit) to the primary unit. However this did not happen, and I needed to issue the "write standby" command on the secondary (active unit) in order for the config sync to commence. Unfortunately at this stage, the primary assumed the active state, which is not what I wanted to happen.
Can someone let me know what the correct way of doing this would be, to ensure the secondary unit would remain active, and simply replicate config to the primary unit, without the primary unit becoming active at any stage.
Thanks,
Charles