FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] PIX stateful failover and separate external circuits

To: firewall-wizards@listserv.icsalabs.com
Subject: Re: [fw-wiz] PIX stateful failover and separate external circuits
From: James Burns <james.burns@sunderland.ac.uk>
Date: Thu, 15 Feb 2007 09:15:15 +0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <45D35744.7010505@andrei.myip.org>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Organization: Student & Learning Support
References: <45D35744.7010505@andrei.myip.org>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.2) Gecko/20040804 Netscape/7.2 (ax)
Hi Florin,

The information you have been given is correct. For a Pix to support 
stateful failover, a dedicated LAN interface between the two units is 
required. You can read more here:

http://www.cisco.com/warp/public/110/failover.html#statefulfailover

Kind regards,
James Burns

Florin Andrei wrote:

>I've a pair of PIX fw's (OS ver 7.2) in a failover configuration. The 
>two external interfaces are connected to the provider on two separate 
>circuits.
>
>The provider claims that in such a configuration, stateful failover will 
>not work (the PIXes will do stateless failover), and we need to hook up 
>a switch (or a pair of switches) between the two firewalls and the two 
>circuits to enable stateful failover.
>
>Somehow that doesn't sound right to me, but I cannot prove it, nor 
>disprove it. Anybody knows what the real answer is? A link to some 
>document that has the details to support the answer would be great, too.
>
>Thanks,
>
>  
>

-- 
James Burns

Network & Security Advisor – Student & Learning Support
University of Sunderland


_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>