05-09-2011 11:57 PM - edited 03-11-2019 01:31 PM
two pix connect by failover cable and state interface.
when we connect failover serial cable , found primary unit inside/outside interface down. state interface is ok.
after we disconnect failover cable, primary unit inside/outdise interface turn up.
primary unit is in standby status.
is there any same problem
thank you!
05-10-2011 12:03 AM
With the serial failover cable, please kindly make sure that you connect the cable end marked with Primary to the Primary PIX and the cable end marked with Secondary to the Secondary PIX correctly.
Also, if that still does not work, maybe the cable is faulty and try to see if you have any spare serial cable for PIX and check if it makes any difference. I assume that this cable used to work earlier?
Finally, if you don't have a spare serial failover cable, then use LAN failover, and just use the same LAN cable that you pass the state information for the failover interface as well.
05-10-2011 12:18 AM
here is show failover from secondary /active PIX, cable status is normal. primary/stanby pix outside/inside interface is down
------------------ show failover ------------------
Failover On
Cable status: Normal
Reconnect timeout 0:00:20
This host: Secondary - Active
Active time: 14186565 (sec)
Interface pix/intf3 (127.0.0.1): Link Down (Waiting)
Interface status (192.168.254.1): Normal (Waiting)
Interface outside (172.16.253.20): Normal (Waiting)
Interface inside (172.16.253.162): Normal (Waiting)
Other host: Primary - Standby (Failed)
Active time: 0 (sec)
Interface pix/intf3 (0.0.0.0): Link Down (Waiting)
Interface status (192.168.254.2): Normal (Waiting)
Interface outside (172.16.253.21): Link Down (Waiting)
Interface inside (172.16.253.163): Link Down (Waiting)
Stateful Failover Logical Update Statistics
Link : outside
Stateful Obj xmit xerr rcv rerr
General 660625431 0 3664930804 0
sys cmd 7136593 0 6685749 0
up time 16 0 0 0
xlate 2363 0 179 0
tcp conn 653478081 0 3658244876 0
udp conn 8378 0 0 0
ARP tbl 0 0 0 0
RIP Tbl 0 0 0 0
Logical Update Queue Information
Cur Max Total
Recv Q: 0 922 3664930804
Xmit Q: 0 698 660625582
05-10-2011 12:28 AM
Is the Primary outside and inside interface actually connected to anything?
Can you please share the following output from the Primary firewall: show interface
Also what is the version of your PIX firewall?
05-10-2011 01:21 AM
thank you!
outside/inside interface actually connect to different switch, after we disconnect failover serial cable, primary pix outside/inside interface up.
05-10-2011 12:30 AM
here is primary/standby show failover command, customer use outside interface as failover stateful interface. because stateful interface is a 100M fast ethernet.
------------------ show failover ------------------
Failover On
Cable status: Normal
Reconnect timeout 0:00:20
This host: Primary - Standby (Failed)
Active time: 0 (sec)
Interface pix/intf3 (0.0.0.0): Link Down (Waiting)
Interface status (192.168.254.2): Normal (Waiting)
Interface outside (172.16.253.21): Link Down (Waiting)
Interface inside (172.16.253.163): Link Down (Waiting)
Other host: Secondary - Active
Active time: 14186880 (sec)
Interface pix/intf3 (127.0.0.1): Failed (Waiting)
Interface status (192.168.254.1): Failed (Waiting)
Interface outside (172.16.253.20): Failed (Waiting)
Interface inside (172.16.253.162): Failed (Waiting)
Stateful Failover Logical Update Statistics
Link : outside
Stateful Obj xmit xerr rcv rerr
General 20 0 0 0
sys cmd 20 0 0 0
up time 0 0 0 0
xlate 0 0 0 0
tcp conn 0 0 0 0
udp conn 0 0 0 0
ARP tbl 0 0 0 0
RIP Tbl 0 0 0 0
Logical Update Queue Information
Cur Max Total
Recv Q: 0 0 0
Xmit Q: 0 1 20
05-10-2011 12:38 AM
here is show interface from primary pix, version is 5.1(2)
------------------ show interface ------------------
interface gb-ethernet0 "outside" is down, line protocol is down
Hardware is gigabit ethernet, address is 0090.27fc.7abc
IP address 172.16.253.20, subnet mask 255.255.255.248
MTU 1500 bytes, BW 1 Gbit full duplex
1 packets input, 1070 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
4 packets output, 1282 bytes, 0 underruns, 0 unicast rpf drops
interface gb-ethernet1 "inside" is down, line protocol is down
Hardware is gigabit ethernet, address is 00d0.b76d.eb2e
IP address 172.16.253.162, subnet mask 255.255.255.248
MTU 1500 bytes, BW 1 Gbit full duplex
1 packets input, 1070 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 1 frame, 0 overrun, 0 ignored, 0 abort
3 packets output, 1218 bytes, 0 underruns, 0 unicast rpf drops
interface ethernet0 "status" is down, line protocol is up
Hardware is i82559 ethernet, address is 0090.2785.bbf1
IP address 192.168.254.1, subnet mask 255.255.255.252
MTU 1500 bytes, BW 100000 Kbit full duplex
25 packets input, 1842 bytes, 0 no buffer
Received 4 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 packets output, 430 bytes, 0 underruns, 0 unicast rpf drops
0 output errors, 0 collisions, 0 interface resets
0 babbles, 0 late collisions, 0 deferred
0 lost carrier, 0 no carrier
interface ethernet1 "pix/intf3" is administratively down, line protocol is down
Hardware is i82559 ethernet, address is 0090.2785.b642
IP address 127.0.0.1, subnet mask 255.255.255.255
MTU 1500 bytes, BW 100000 Kbit full duplex
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 packets output, 0 bytes, 0 underruns, 0 unicast rpf drops
0 output errors, 0 collisions, 0 interface resets
0 babbles, 0 late collisions, 0 deferred
0 lost carrier, 0 no carrier
05-10-2011 01:34 AM
All the status of the interfaces are showing it's down, hence the show failover will report it's down.
Please check the connectivity between the PIX interfaces with the switch.
You have to see "interface gb-ethernet0 "outside" is up, line protocol is up" for all interfaces for failover to work.
At the moment, they are all showing down.
05-10-2011 02:00 AM
yes,but after we disconnect failover serial cable , primary pix outsite/insite interface will come up.
05-10-2011 02:03 AM
Then that definitely sounds like a faulty cable.
Try to configure LAN based failover so you don't have to use the serial cable.
05-10-2011 02:36 AM
i will try it , thank you!
05-11-2011 08:14 PM
we have replaced failover serial cable, it is not work.
05-11-2011 08:22 PM
Please try to configure using LAN based failover and see if you are seeing the same error.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide