virtual I.P on PiX DMZ interface
Posted on 2009-04-01
I have 2 PIX firewalls ...
I want to know that just like we have virtual I.P's in HSRP and clients point to that virtual I.P, can we have something similar or like that in PIX firewall as well ? Reason am asking is because the scenario is where ive two PIX firewalls and behind each fix pirewalls is a router (smthg like this given below)
Router 1--> Pix 1--> Internet
Router 2--> Pix 2--> Internet
I want to run HSRP on both routers and only issue I see is that in case of an hsrp failover (i.e. router 1 fails and router 2 becomes the active one), servers in dmz will keep forwarding traffic to Pix 1 DMZ Interface I.P (coz its not gonna know when the HSRP has failed over) whereas it should be sending traffic to Pix 2 DMZ I.P since thats the active one now !
Was i able to explain the issue ?