02-06-2003 12:25 PM - edited 02-20-2020 10:32 PM
I have a PIX 515 that was running a Failover license, V6.2(2). We are going to use it as a standalone PIX at another office. I bought a failover to restricted license and received the new activation-key from Cisco. The config was erased and a new activation key was installed for the restricted license. The PIX was rebooted and a "show ver" showed the activation key was correct. Also, the maximum interfaces shows 3.
Next, a config was uploaded from tftp to the PIX. This config was running on a Restricted 515 passing traffic fine. The old restricted PIX was swapped out and replaced with the PIX that was our Failover. Traffic is not being passed from the LAN to the Internet. The PIX can ping to the Internet and the PIX can ping the LAN. But traffic will not pass through it. The config was checked against the old PIX that was running. It matched line for line. The NAT and Global commands are fine. When a capture command is perfomed on the inside ethernet, you can see PAT happening from the inside towards the Internet, but the web browser just times out.
Does anyone have any suggestions? Or are there any bugs on upgading the PIX from FO to R?
Thanks,
RJ
02-06-2003 06:24 PM
Can you post the important parts of the config?
02-07-2003 12:08 AM
The config is identical to our other PIX 515 that was running fine with a restricted license with 3 interfaces. The new PIX is a 515 with 3 interfaces that is now running a restricted license upgraded from a failover license. The only variables (possible problems) would be:
1. The upgrade process, (the activation key process).
2. Erasing the config, upgrading the key and then uploading the working config from the old PIX.
I am wondering if there are steps that need to be performed in a certain order or an upgrade bug.
Thanks,
RJ
02-07-2003 03:33 AM
Hi,
I also got problems with licence uprades in the past. Please check the licnece entries in the "sh ver output". Maybe your activation key was not correct in licencing the features correctly. At any question respond to the mail, you got the key from and describe your problem.
On the other hand, did your pix work fine in failover mode? perhaps you have a hardware problem which never occured because your failover was never in use?
Hope this helps
Best regards Norbert Steup
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide