cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
224
Views
5
Helpful
1
Replies

Stateful failover not working

dharris
Level 1
Level 1

IMO, stateful failover means active TCP connections are retained and, once the firewall fails over there might be a small blip, but eg downloads will resume.

This does not appear to be the case on a PIX. I have configured cable based, and stateful failover using dedicated interfaces and can see the state table being populated. 2950 switches have been also set and verified. The firewalls certainly failover, however, state is not retained and downloads break and have to be restarted from scratch.

So.... has anyone had a PIX configured to do this?

If so, please enlighten me with a how to.

1 Reply 1

sachinraja
Level 9
Level 9

Hello harris,

Cisco says:

stateful failover passes on the PIX address translation (xlate,static & dynamic) and connection records that are essential for the user operation, to the standby PIX.

TCP state tables are transferred, however by default http (TCP port 80) is not replicated. since all the downloads are http based, the replication is not done by default. in versions 6.0 and later, you can force this by using the command "failover replicate http"

just try this and see if it works out for you..

All the best..

Raj