Cisco PIX 525 Specifikace Strana 136

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 604
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 135
11-4
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Understanding Failover
On systems running in multiple context mode, the failover link resides in the system context. This
interface and the state link, if used, are the only interfaces that you can configure in the system context.
All other interfaces are allocated to and configured from within security contexts.
Note The IP address and MAC address for the failover link do not change at failover.
Serial Cable Failover Link (PIX Security Appliance Only)
The serial Failover cable, or “cable-based failover,” is only available on the PIX security appliance
platform. If the two units are within six feet of each other, then we recommend that you use the serial
Failover cable.
The cable that connects the two units is a modified RS-232 serial link cable that transfers data at
117,760 bps (115 Kbps). One end of the cable is labeled “Primary”. The unit attached to this end of the
cable automatically becomes the primary unit. The other end of the cable is labeled “Secondary”. The
unit attached to this end of the cable automatically becomes the secondary unit. You cannot override
these designations in the PIX security appliance software. If you purchased a PIX security appliance
failover bundle, this cable is included. To order a spare, use part number PIX-FO=.
The benefits of using cable-based failover include:
The PIX security appliance can immediately detect a power loss on the peer unit, and to differentiate
a power loss from an unplugged cable.
The standby unit can communicate with the active unit and can receive the entire configuration
without having to be bootstrapped for failover. In LAN-based failover you need to configure the
failover link on the standby unit before it can communicate with the active unit.
The switch between the two units in LAN-based failover can be another point of hardware failure;
cable-based failover eliminates this potential point of failure.
You do not have to dedicate an Ethernet interface (and switch) to the failover link.
The cable determines which unit is primary and which is secondary, eliminating the need to
manually enter that information in the unit configurations.
The disadvantages include:
Distance limitation—the units cannot be separated by more than 6 feet.
Slower configuration replication.
State Link
To use Stateful Failover, you must configure a state link to pass all state information. You have two
options for configuring a state link: you can use any unused Ethernet interface as a dedicated state link
or, if you are using LAN-based failover, you can use the failover link. When using a dedicated state link,
you cannot specify an interface that is currently configured with a name.
The state link interface is not configured as a normal networking interface; it exists only for Stateful
Failover communications and, optionally, for the failover communication if you share the state and
failover links. You can connect the state link by using a dedicated switch with no hosts or routers on the
link or by using a crossover Ethernet cable to link the units directly.
Zobrazit stránku 135
1 2 ... 131 132 133 134 135 136 137 138 139 140 141 ... 603 604

Komentáře k této Příručce

Žádné komentáře