I would assume that your two ISP circuits have different IP address
assignments? If so, I do not believe that the PIX can failover connection
states to an Interface with a different IP address than the original.
Thanks,
Paul Murphy
Florin Andrei
<florin@andrei.my
ip.org> To
Sent by: firewall-wizards@listserv.icsalabs.
firewall-wizards- com
bounces@listserv. cc
icsalabs.com
Subject
[fw-wiz] PIX stateful failover and
02/14/2007 05:36 separate external circuits
PM
Please respond to
firewall-wizards@
listserv.icsalabs
.com
I've a pair of PIX fw's (OS ver 7.2) in a failover configuration. The
two external interfaces are connected to the provider on two separate
circuits.
The provider claims that in such a configuration, stateful failover will
not work (the PIXes will do stateless failover), and we need to hook up
a switch (or a pair of switches) between the two firewalls and the two
circuits to enable stateful failover.
Somehow that doesn't sound right to me, but I cannot prove it, nor
disprove it. Anybody knows what the real answer is? A link to some
document that has the details to support the answer would be great, too.
Thanks,
--
Florin Andrei
http://florin.myip.org/
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [fw-wiz] Need help configuring client-side VPN to Cisco 2801, Mike Leone |
|---|---|
| Next by Date: | Re: [fw-wiz] PIX stateful failover and separate external circuits, James Burns |
| Previous by Thread: | [fw-wiz] Need help configuring client-side VPN to Cisco 2801, Mike Leone |
| Next by Thread: | Re: [fw-wiz] PIX stateful failover and separate external circuits, James Burns |
| Indexes: | [Date] [Thread] [Top] [All Lists] |