cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1212
Views
0
Helpful
12
Replies

pix520 failover weird problem

fly
Level 7
Level 7

two pix connect by failover cable and state interface.

when we connect failover serial cable , found primary unit inside/outside interface down.  state interface is ok.

after we disconnect failover cable, primary unit inside/outdise interface turn up.

primary unit is in standby status.

is there any same problem

thank you!

12 Replies 12

Jennifer Halim
Cisco Employee
Cisco Employee

With the serial failover cable, please kindly make sure that you connect the cable end marked with Primary to the Primary PIX and the cable end marked with Secondary to the Secondary PIX correctly.

Also, if that still does not work, maybe the cable is faulty and try to see if you have any spare serial cable for PIX and check if it makes any difference. I assume that this cable used to work earlier?

Finally, if you don't have a spare serial failover cable, then use LAN failover, and just use the same LAN cable that you pass the state information for the failover interface as well.

here is show failover from secondary /active PIX, cable status is normal.   primary/stanby pix outside/inside interface is down

------------------ show failover ------------------

Failover On

Cable status: Normal

Reconnect timeout 0:00:20

        This host: Secondary - Active

                Active time: 14186565 (sec)

                Interface pix/intf3 (127.0.0.1): Link Down (Waiting)

                Interface status (192.168.254.1): Normal (Waiting)

                Interface outside (172.16.253.20): Normal (Waiting)

                Interface inside (172.16.253.162): Normal (Waiting)

        Other host: Primary - Standby (Failed)

                Active time: 0 (sec)

                Interface pix/intf3 (0.0.0.0): Link Down (Waiting)

                Interface status (192.168.254.2): Normal (Waiting)

                Interface outside (172.16.253.21): Link Down (Waiting)

                Interface inside (172.16.253.163): Link Down (Waiting)

Stateful Failover Logical Update Statistics

        Link : outside

        Stateful Obj    xmit       xerr       rcv        rerr    

        General         660625431  0          3664930804 0       

        sys cmd         7136593    0          6685749    0       

        up time         16         0          0          0       

        xlate           2363       0          179        0       

        tcp conn        653478081  0          3658244876 0       

        udp conn        8378       0          0          0       

        ARP tbl         0          0          0          0       

        RIP Tbl         0          0          0          0       

        Logical Update Queue Information

                        Cur     Max     Total

        Recv Q:         0       922     3664930804

        Xmit Q:         0       698     660625582

Is the Primary outside and inside interface actually connected to anything?

Can you please share the following output from the Primary firewall: show interface

Also what is the version of your PIX firewall?

thank you!

outside/inside interface actually connect to different switch, after we disconnect failover serial cable, primary pix outside/inside interface up.

here is primary/standby show failover command,  customer use outside interface as failover stateful interface. because stateful interface is a 100M fast ethernet.

------------------ show failover ------------------

Failover On

Cable status: Normal

Reconnect timeout 0:00:20

        This host: Primary - Standby (Failed)

                Active time: 0 (sec)

                Interface pix/intf3 (0.0.0.0): Link Down (Waiting)

                Interface status (192.168.254.2): Normal (Waiting)

                Interface outside (172.16.253.21): Link Down (Waiting)

                Interface inside (172.16.253.163): Link Down (Waiting)

        Other host: Secondary - Active

                Active time: 14186880 (sec)

                Interface pix/intf3 (127.0.0.1): Failed (Waiting)

                Interface status (192.168.254.1): Failed (Waiting)

                Interface outside (172.16.253.20): Failed (Waiting)

                Interface inside (172.16.253.162): Failed (Waiting)

Stateful Failover Logical Update Statistics

        Link : outside

        Stateful Obj    xmit       xerr       rcv        rerr    

        General         20         0          0          0       

        sys cmd         20         0          0          0       

        up time         0          0          0          0       

        xlate           0          0          0          0       

        tcp conn        0          0          0          0       

        udp conn        0          0          0          0       

        ARP tbl         0          0          0          0       

        RIP Tbl         0          0          0          0       

        Logical Update Queue Information

                        Cur     Max     Total

        Recv Q:         0       0       0

        Xmit Q:         0       1       20

here is show interface from primary pix, version is 5.1(2)

------------------ show interface ------------------
             
interface gb-ethernet0 "outside" is down, line protocol is down
  Hardware is gigabit ethernet, address is 0090.27fc.7abc
  IP address 172.16.253.20, subnet mask 255.255.255.248
  MTU 1500 bytes, BW 1 Gbit full duplex
        1 packets input, 1070 bytes, 0 no buffer
        Received 0 broadcasts, 0 runts, 0 giants
        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
        4 packets output, 1282 bytes, 0 underruns, 0 unicast rpf drops
interface gb-ethernet1 "inside" is down, line protocol is down
  Hardware is gigabit ethernet, address is 00d0.b76d.eb2e
  IP address 172.16.253.162, subnet mask 255.255.255.248
  MTU 1500 bytes, BW 1 Gbit full duplex
        1 packets input, 1070 bytes, 0 no buffer
        Received 0 broadcasts, 0 runts, 0 giants
        0 input errors, 0 CRC, 1 frame, 0 overrun, 0 ignored, 0 abort
        3 packets output, 1218 bytes, 0 underruns, 0 unicast rpf drops
interface ethernet0 "status" is down, line protocol is up
  Hardware is i82559 ethernet, address is 0090.2785.bbf1
  IP address 192.168.254.1, subnet mask 255.255.255.252
  MTU 1500 bytes, BW 100000 Kbit full duplex
        25 packets input, 1842 bytes, 0 no buffer
        Received 4 broadcasts, 0 runts, 0 giants
        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
        0 packets output, 430 bytes, 0 underruns, 0 unicast rpf drops
        0 output errors, 0 collisions, 0 interface resets
        0 babbles, 0 late collisions, 0 deferred
        0 lost carrier, 0 no carrier
interface ethernet1 "pix/intf3" is administratively down, line protocol is down
  Hardware is i82559 ethernet, address is 0090.2785.b642
  IP address 127.0.0.1, subnet mask 255.255.255.255
  MTU 1500 bytes, BW 100000 Kbit full duplex
        0 packets input, 0 bytes, 0 no buffer
        Received 0 broadcasts, 0 runts, 0 giants
        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
        0 packets output, 0 bytes, 0 underruns, 0 unicast rpf drops
        0 output errors, 0 collisions, 0 interface resets
        0 babbles, 0 late collisions, 0 deferred
        0 lost carrier, 0 no carrier

All the status of the interfaces are showing it's down, hence the show failover will report it's down.

Please check the connectivity between the PIX interfaces with the switch.

You have to see "interface gb-ethernet0 "outside" is up, line protocol is up" for all interfaces for failover to work.

At the moment, they are all showing down.

yes,but after we disconnect failover serial cable , primary pix outsite/insite interface will come up.

Then that definitely sounds like a faulty cable.

Try to configure LAN based failover so you don't have to use the serial cable.

i will try it , thank you!

we have replaced failover serial cable, it is not work.

Please try to configure using LAN based failover and see if you are seeing the same error.

Review Cisco Networking for a $25 gift card