cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
482
Views
0
Helpful
1
Replies

Ipsec failover in PIX ver 6.3

WE have pix 515e with FOS 6.3 ,We need to have two vpn tunnels in place from this pix to the same peer in a failover scenario ie if one VPN fails over one link another VPN configured over another link to the same peer takes over

The peer is also a PIX ver 6.3

Any pointers advise would be appreciated

Thanks and regards

1 Reply 1

jsivulka
Level 5
Level 5

The ISAKMP and IPSec SA table are not replicated to the standby PIX Firewall on Stateful Failover. ( see documentation for 6.3 at http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/failover.htm). Thus after failover, the tunnel willl have to be re-built, during which you will not have IPSec connectivity to the remote site.