« Return to Thread: PIX failover disable help
There is a failover poll interval of 15 seconds (after version 5.0 it is configurable) to monitor network activity, failover communications, and the power status. A failure of any of these parameters on the active unit causes the standby unit to take active control. Whenever a unit is determined to have failed, it shuts down its network interfaces.
The two units send special failover "hello" packets to each other over the failover cable and all interfaces every 15 seconds (excludes those that are administratively shutdown). If either unit does not hear the "hello" on an interface for two consecutive poll checks, the PIX puts that LAN interface into testing mode in order to determine where the fault lies. If a standby PIX does not receive a "hello" from the failover cable for two consecutive poll checks, the standby PIX initiates a switchover and declares the other PIX failed. If the active PIX does not hear the "hello" messages, it stays active and sets the other PIX as failed.
Thank You,
sivakumar escribió:I have a pix stateful failover(6.3) set up in active/standby mode. Now ijust want to shut down an interface on the failover and bring back it tounused state. Now i'm worried if by giving a shut on the interface on theactive pix would affect the standby and would drive them to panic.As per the document i'm thinking of to disable the failover first and shutthe interface on pri and then sec and after that would enable back thefailover again. Would that be fine or it would still affect and make aswitch over.My concern is if we disable the failover the 2 pixes would poll using theother ethernet interfaces to check they are up. And if i shut down an int,would that make the pix to failover and standby to active?[B]Could you please tell me a safe way so that i could rid of it withoutaffecting any live traffic?[/B]-----Regards,SivaJust shut down the interface in the active unit, that won't trigger the
failover algorithm, and the configuration will be propagated to the
secondary/standby unit. As there's no live traffic going on by that
interface no live traffic should be affected.
Greetings,
Nico
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
« Return to Thread: PIX failover disable help
| Free embeddable forum powered by Nabble | Forum Help |