PIX stateful failover config help

I wish to implement a failover between two 515e's

It needs to be stateful.

failover ip address inside 192.168.1.x
failover ip address outside 217.xxx.xxx.x

nameif ethernet2 state security25
interface ethernet2 100full

ip address state 217.xxx.xxx.x 255.255.255.0
failover ip address state 217.xxx.xx.x
failover link state


Is this config correct? or is there anything else I need to add. Also do I need to put any config on the second PIX?

Thanks
supportguy99Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Tim HolmanCommented:
Complete instructions here:

http://www.cisco.com/warp/public/110/failover.html

You can only achieve stateful failover if you configure over the LAN, instead of going via the failover cable.
kbbcnetCommented:
Previous EE Solution may be helpful as well.
Setting up failover on Cisco PIX 515E firewalls:
http://www.experts-exchange.com/Networking/Q_20716348.html
kbbcnetCommented:
Previous EE Solution:
Ciso PIX 515e in Failover Config- Walkthrough:
http://www.experts-exchange.com/Security/Firewalls/Q_21326240.html

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008017278a.html
---------------------------

<I wish to implement a failover between two 515e's ... It needs to be stateful.>
Config/Example -- Failover Communication --  
Frequently Asked Failover Questions -- Stateful Failover Questions --
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_61/config/failover.htm
Your Guide to Achieving IT Business Success

The IT Service Excellence Tool Kit has best practices to keep your clients happy and business booming. Inside, you’ll find everything you need to increase client satisfaction and retention, become more competitive, and increase your overall success.

supportguy99Author Commented:
Ive read all those guides before....I just want to know if what I've written down is correct.
Tim HolmanCommented:
For stateful failover, you need LAN-based failover to be setup, so:

http://www.cisco.com/warp/public/110/failover.html#lanbasedfailover

What you've written down is incomplete.  You need one interface on each unit to share heartbeat information, and a second one to share state:

PRIMARY

hostname PIX                                
nameif ethernet2 fo security20                
interface ethernet2 100full                            
ip address fo 192.168.1.1 255.255.255.0  
failover ip address fo 192.168.1.2
failover lan unit primary                
failover lan interface fo                
failover lan key cisco                    
failover lan enable                          
failover                                
ip address stateful-fo 172.16.1.1 255.255.255.0
interface ethernet3 100full
failover ip address stateful-fo 172.16.1.2
failover link stateful-fo

SECONDARY

hostname PIX
nameif ethernet2 fo security20
interface ethernet2 100full
ip address fo 192.168.1.1 255.255.255.0
failover ip address fo 192.168.1.2
failover lan unit secondary                    
failover lan interface fo
failover lan key cisco
failover lan enable
failover
ip address stateful-fo 172.16.1.2 255.255.255.0
nameif ethernet3 stateful-fo security30
interface ethernet3 100full

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
supportguy99Author Commented:
But the LAN connection can just be a crossover cable?

and I would still use the failover cable too.
Tim HolmanCommented:
You need to connect using a switch.  Crossover cables are not recommended.
Using a failover cable for the heartbeats, and LAN cable for state sharing is fine.
kbbcnetCommented:
Do you need more information?
Have you resolved this problem?
Can you close this question?
Thanks!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.