
11-20
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 11 Configuring Failover
Configuring Failover
To configure the secondary unit, perform the following steps:
Step 1 (PIX security appliance platform only) Enable LAN-based failover.
hostname(config)# failover lan enable
Step 2 Define the failover interface. Use the same settings as you used for the primary unit.
a. Specify the interface to be used as the failover interface.
hostname(config)# failover lan interface
if_name
phy_if
The if_name argument assigns a name to the interface specified by the phy_if argument.
b. Assign the active and standby IP address to the failover link.
hostname(config)# failover interface ip
if_name ip_addr mask
standby
ip_addr
Note Enter this command exactly as you entered it on the primary unit when you configured the
failover interface on the primary unit.
c. Enable the interface.
hostname(config)# interface
phy_if
hostname(config-if)# no shutdown
Step 3 (Optional) Designate this unit as the secondary unit.
hostname(config)# failover lan unit secondary
Note This step is optional because by default units are designated as secondary unless previously
configured.
Step 4 Enable failover.
hostname(config)# failover
After you enable failover, the active unit sends the configuration in running memory to the standby unit.
As the configuration synchronizes, the messages “Beginning configuration replication: Sending to mate”
and “End Configuration Replication to mate” appear on the active unit console.
Step 5 After the running configuration has completed replication, save the configuration to Flash memory.
hostname(config)# copy running-config startup-config
Configuring Optional Active/Standby Failover Settings
You can configure the following optional Active/Standby failover setting when you are initially
configuring failover or after failover has already been configured. Unless otherwise noted, the
commands should be entered on the active unit.
Komentáře k této Příručce