License Requirements
On the PIX 500 series security appliance, at least one of the units must have an unrestricted (UR) license. The other unit can have a Failover Only (FO) license, a Failover Only Active-Active (FO_AA) license, or another UR license. Units with a Restricted license cannot be used for failover, and two units with FO
or FO_AA licenses cannot be used together as a failover pair. ^ _
Note The FO license does not support Active/Active failover.
|
The FO and FO_AA licenses are intended to be used solely for units in a failover configuration and not for units in standalone mode. If a failover unit with one of these licenses is used in standalone mode, the unit reboots at least once every 24 hours until the unit is returned to failover duty. A unit with an FO or FO_AA license operates in standalone mode if it is booted without being connected to a failover peer with a UR license. If the unit with a UR license in a failover pair fails and is removed from the configuration, the unit with the FO or FO_AA license does not automatically reboot every 24 hours; it operates uninterrupted unless the it is manually rebooted. |
|
|
When the unit automatically reboots, the following message displays on the console: |
|
|
-------------------------NOTICE------------------------- This machine is running in secondary mode without a connection to an active primary PIX. Please check your connection to the primary system. |
|
|
REBOOTING |
|
|
The ASA 5500 series adaptive security appliance platform does not have this restriction. |
|
|
The Failover and Stateful Failover Links |
|
|
This section describes the failover and the Stateful Failover links, which are dedicated connections between the two units in a failover configuration. This section includes the following topics: |
|
|
• Failover Link, page 14-3 |
|
|
• Stateful Failover Link, page 14-5 |
|
|
Failover Link |
The two units in a failover pair constantly communicate over a failover link to determine the operating status of each unit. The following information is communicated over the failover link: • The unit state (active or standby). • Power status (cable-based failover only—available only on the PIX 500 series security appliance). • Hello messages (keep-alives). • Network link status. • MAC address exchange. |
|
A |
• Configuration replication and synchronization. |
|
Caution |
All information sent over the failover and Stateful Failover links is sent in clear text unless you secure the communication with a failover key. If the security appliance is used to terminate VPN tunnels, this information includes any usernames, passwords and preshared keys used for establishing the tunnels. Transmitting this sensitive data in clear text could pose a significant security risk. We recommend securing the failover communication with a failover key if you are using the security appliance to terminate VPN tunnels. |
|
On the PIX 500 series security appliance, the failover link can be either a LAN-based connection or a dedicated serial Failover cable. On the ASA 5500 series adaptive security appliance, the failover link can only be a LAN-based connection. |
|
|
This section includes the following topics: |
|
|
Cisco Security Appliance Command Line Configuration Guide g |
|
|
1 0L-10088-02 |
|
• LAN-Based Failover Link, page 14-4
• Serial Cable Failover Link (PIX Security Appliance Only), page 14-4 LAN-Based Failover Link
You can use any unused Ethernet interface on the device as the failover link. You cannot specify an interface that is currently configured with a name. The failover link interface is not configured as a normal networking interface; it exists only for failover communication. This interface should only be used for the failover link (and optionally for the Stateful Failover link). You can connect the LAN-based failover link by using a dedicated switch with no hosts or routers on the link or by using a crossover
Ethernet cable to link the units directly. % _
Note When using VLANs, use a dedicated VLAN for the failover link. Sharing the failover link VLAN with any other VLANs can cause intermittent traffic problems and ping and ARP failures. If you use a switch to connect the failover link, use dedicated interfaces on the switch and security appliance for the failover link; do not share the interface with subinterfaces carrying regular network traffic.
On systems running in multiple context mode, the failover link resides in the system context. This interface and the Stateful Failover link, if used, are the only interfaces that you can configure in the system context. All other interfaces are allocated to and configured from within security contexts. % _
Note The IP address and MAC address for the failover link do not change at failover.
Serial Cable Failover Link (PIX Security Appliance Only)
The serial Failover cable, or "cable-based failover," is only available on the PIX 500 series security appliance. If the two units are within six feet of each other, then we recommend that you use the serial Failover cable.
The cable that connects the two units is a modified RS-232 serial link cable that transfers data at 117,760 bps (115 Kbps). One end of the cable is labeled "Primary". The unit attached to this end of the cable automatically becomes the primary unit. The other end of the cable is labeled "Secondary". The unit attached to this end of the cable automatically becomes the secondary unit. You cannot override these designations in the PIX 500 series security appliance software. If you purchased a PIX 500 series security appliance failover bundle, this cable is included. To order a spare, use part number PIX-FO=.
The benefits of using cable-based failover include:
• The PIX 500 series security appliance can immediately detect a power loss on the peer unit and differentiate between a power loss from an unplugged cable.
• The standby unit can communicate with the active unit and can receive the entire configuration without having to be bootstrapped for failover. In LAN-based failover you need to configure the failover link on the standby unit before it can communicate with the active unit.
• The switch between the two units in LAN-based failover can be another point of hardware failure; cable-based failover eliminates this potential point of failure.
• You do not have to dedicate an Ethernet interface (and switch) to the failover link.
• The cable determines which unit is primary and which is secondary, eliminating the need to manually enter that information in the unit configurations.
The disadvantages include:
• Distance limitation—the units cannot be separated by more than 6 feet.
• Slower configuration replication.
Continue reading here: Stateful Failover Link
Was this article helpful?