FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] PIX stateful failover and separate external circuits

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] PIX stateful failover and separate external circuits
From: Florin Andrei <florin@andrei.myip.org>
Date: Fri, 16 Feb 2007 09:31:39 -0800
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <45D424A3.6020009@sunderland.ac.uk>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <45D35744.7010505@andrei.myip.org> <45D424A3.6020009@sunderland.ac.uk>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Thunderbird 1.5.0.9 (X11/20070212)
James Burns wrote:
> Hi Florin,
> 
> The information you have been given is correct. For a Pix to support 
> stateful failover, a dedicated LAN interface between the two units is 
> required. You can read more here:
> 
> http://www.cisco.com/warp/public/110/failover.html#statefulfailover

Exactly. I just realized I've seen this a while ago - I had a pair of 
PIXes in a failover configuration, each one connected to a different 
switch, and the inter-connection between switches broke. The firewalls 
went nuts trying to kickstart the failover process.

So yeah, the interfaces of the primary and the secondary need to be in 
the same LAN segment.

-- 
Florin Andrei

http://florin.myip.org/
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>