Hi Irmoore,
I understand that both need to be identical.
Primary - PIX 515E UR
Secondary - PIX 515E FO
Both will have same number of interfaces, same IOS and same amount of interfaces.
I understand the principles of how it works, but am unsure of how you would set it up on the network. (sorry i didnt word the question very well)
I am going to go down the statefull FO approach (i have vpn traffic and ssl data and i dont want to terminate sessions)
I will have
I suppose my question was more to do with the switch setup, cisco have used a 3500 catalyst, (i have one i can use) would i take the interface for the DMZ1 from both PIX's into the catalyst 3500, and then take another port from the 3500 into the switch for the DMZ?
What sort of configuration needs to be done on the switch, being failrly new to all this, would anyone be able to shed some light on what cisco mean by Fa3/1 and Fa2/1?
Rob
Main Topics
Browse All Topics





by: lrmoorePosted on 2003-09-08 at 17:57:20ID: 9313716
Yes. You need to make sure the failover PIX is identical to the primary to include the extra 2 interfaces. Ideally, you would have a 5th on each one to support stateful failover, but it works without.
What happens is that you only configure the primary. When you save the config, it is saved to the secondary automatically. When failover happens, the secondary assumes the total identity of the primary including all IP addresses and MAC addresses for every interface.
The GIF above actually shows all 4 interfaces on both PIX's..