Do not use on any
shared computer
August 29, 2008 11:07pm pdt
 
[x]
Attachment Details

PIX Failover Issue

Tags: pix, add, route, failover
I am having an issue setting up failover between two PIX 515E units.  My primary unit has an UR license and the secondary unit has a FO only license.  I am not performing stateful failover and I am using the PIX failover cable between the two units.

My primary pix has an internal IP of 192.168.1.1 / 16.

Here are the commands I used to attempt setting up failover:
On the failover unit I erased the current config with the write erase command.  I then powered off my failover unit and cabled the two appropriately.

On the Primary unit I entered the folowing commands:
failover ip address outside xx.xx.xx.81
failover ip address inside 192.168.1.5
failover active
write mem

I received the following error:
WARNING: unable to add route to OSPF RIB

Here is the output of the show ver command on both units:



Primary PIX

Cisco PIX Firewall Version 6.3(5)
Cisco PIX Device Manager Version 3.0(4)

Compiled on Thu 04-Aug-05 21:40 by morlee

helm-pix01config up 1 day 21 hours

Hardware:   PIX-515E, 64 MB RAM, CPU Pentium II 433 MHz
Flash E28F128J3 @ 0x300, 16MB
BIOS Flash AM29F400B @ 0xfffd8000, 32KB

Encryption hardware device : VAC+ (Crypto5823 revision 0x1)
0: ethernet0: address is 0011.5cfa.2a52, irq 10
1: ethernet1: address is 0011.5cfa.2a53, irq 11
Licensed Features:
Failover:                    Enabled
VPN-DES:                     Enabled
VPN-3DES-AES:                Enabled
Maximum Physical Interfaces: 6
Maximum Interfaces:          10
Cut-through Proxy:           Enabled
Guards:                      Enabled
URL-filtering:               Enabled
Inside Hosts:                Unlimited
Throughput:                  Unlimited
IKE peers:                   Unlimited

This PIX has an Unrestricted (UR) license.

Serial Number: 808254341 (0x302cfb85)
Running Activation Key: 0xa626edba 0xd0e4767f 0x233acf49 0xe4250d81
Configuration last modified by enable_15 at 12:12:46.924 UTC Sat Nov 3 2007
helm-pix01config>


*****************************************************************************************************************
Failover PIX

Cisco PIX Firewall Version 6.3(5)
Cisco PIX Device Manager Version 3.0(4)

Compiled on Thu 04-Aug-05 21:40 by morlee

pixfirewall up 1 day 22 hours

Hardware:   PIX-515E, 64 MB RAM, CPU Pentium II 433 MHz
Flash E28F128J3 @ 0x300, 16MB
BIOS Flash AM29F400B @ 0xfffd8000, 32KB

0: ethernet0: address is 0011.5cfa.2a52, irq 10
1: ethernet1: address is 0011.5cfa.2a53, irq 11
Licensed Features:
Failover:                    Enabled
VPN-DES:                     Enabled
VPN-3DES-AES:                Enabled
Maximum Physical Interfaces: 6
Maximum Interfaces:          10
Cut-through Proxy:           Enabled
Guards:                      Enabled
URL-filtering:               Enabled
Inside Hosts:                Unlimited
Throughput:                  Unlimited
IKE peers:                   Unlimited

This PIX has a Failover Only (FO) license.

Serial Number: 809302186 (0x303cf8aa)
Running Activation Key: 0xdc552b1b 0x23127c6b 0x11768095 0x74f70eaf
Configuration last modified by enable_15 at 12:28:34.912 UTC Sat Nov 3 2007
pixfirewall(config)#


If anyone can pinpoint where I went wrong I would greatly appreciate it!

Thanks,

Jude
Start your free trial to view this solution
Question Stats
Zone: Security
Question Asked By: jmdowling
Question Asked On: 11.05.2007
Participating Experts: 1
Points: 500
Views: 0
Translate:
Loading Advertisement...
 
[+][-]Expert Comment by Voltz-dk

Rank: Guru

Expert Comment by Voltz-dk:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Author Comment by jmdowling
Author Comment by jmdowling:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Expert Comment by Voltz-dk

Rank: Guru

Expert Comment by Voltz-dk:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
20080723-EE-VQP-34 / EE_QW_2_20070628