05-19-2005 04:06 AM - edited 02-21-2020 12:09 AM
Hi. I have two PIX 515E firewalls. Each has a connection to a router via the outside interface and on the inside to two Cat 6506's. The PIX's are connected via a failover cable and is stateful. I have an ISDN router on a DMZ on the primary PIX, which has a single Fastethernet port so there is no connection to the secondary PIX. How does this affect my failover. If the primary PIX fails over to the secondary PIX, but the secondary PIX does not have a connection to the single attached ISDN router. How can I do this without having to change my ISDN router to one that has two ethernet ports.
05-19-2005 04:14 AM
You should use a hub or a separate switch to connect both pix DMZ-interfaces and the router.
You could even use a separate Ethernet VLAN from the 6509. Doing this will not really improve fault tolerance while you are adding non fault-tolerant components to the system but it does protect you from PIX failure.
Regards,
Leo
05-23-2005 04:13 AM
Hi. Thanks, both ways work well, however as you stated there is now still a single point of failure. I may look at upgrading the router at some later stage. Thanks once again.
Vids
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide