Avatar of Bigchingan
Bigchingan asked on

Cisco PIX 515E - Need to configure replacement Primary unit in Failover config for upcomming swap

We have two Cisco PIX 515E's in a failover configuration protecting our network. Recently, the primary had some hardware failures, and the secondary picked up the slack and is now functioning as the active firewall. Cisco has sent us a replacement firewall, and I've updated the flash and installed the necessary hardware and licenses on it. According to their Tech, basically all I have to do is to get it up and running in production is configure the failover connection on the replacement. Once properly configured, it's a simple matter of swapping out the two firewalls and letting the secondary (active) firewall push it's configuration to the new primary (which would be in standby at that point).

Couple of questions:

Firstly, the replacement firewall is already set as a secondary firewall, and I can't seem to update that with the CLI. How would I go about changing that to make it the official Primary firewall (albeit in a standby mode) so when I connect it in the configuration, it's already setup?

Second. Do I need to to have the "show failover" output on my replacement firewall mimic the failed one exactly as it was before ? AKA, do I have to go as far as configuring all of the interfaces, or is getting the failover on and unit listed as primary the only concerns?

Does anyone have any pointers based off of a similar situation?

I'm running PIX 515E's in a serial attached failover with an extra 4 port NIC card. The new primary firewall (replacement ) is running the 7.1(2) firmware. The secondary is running 7.1(2)60 (I couldn't find this exact firmware when updating the replacement).

CiscoHardware Firewalls

Avatar of undefined
Last Comment

8/22/2022 - Mon

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes