I' running a VPN between a pair of PIX515E w/ 6.3.1 in LAN-based FO and a 1721 VPN router. My VPN tunnel is up and works fine both ways. I force a failover to the standby by pulling one of the cables on the Primary and the failover works fine and the VPN tunnel works. I'm testing via PING.
I have 2 isssues. 1) Ping resumes fine, but FTP or Telnet doesn't. 2) When I plug the ole Primary back in and force the failover back using "failover active", the Primary resumes as the "primary", but nothing works anymore, PING, Telnet, HTTP. Even if I stop the ping and re-initiate the ping it doesn't work.
The only way it will work is if I clear both the IKE and IPSEC SA's on the PIX and 1721 Router.
in my failover config I'm using LAN-based and configured used the 'failover mac address' command.
I've seen some cookbook configs were the command 'route-map' is on the vpn router, I don't have this configured on mine. Can't see why that would make a difference.