Enabling Failover on Primary PIX goes standby.

I have to connect 2 PIX's (515E) with FAILOVER via LAN

After configuring all failover IP addresse and connecting the FAILOVER link to the switch I enabled FAILOVER on the PIX. The PIX goes immediately in standby mode. I thought I should stay active because it's the primary and he couldn't reaching the secondary.

Any suggestion or solution?

pix1(config)# sh failover Failover On Serial Failover Cable status: My side not connected Reconnect timeout 0:00:00 Poll frequency 15 seconds Last Failover at: 22:57:07 CET Mon Nov 7 2005 This host: Primary - Standby Active time: 0 (sec) Interface outside (x.y.9.14): Normal (Waiting) Interface inside (x.y.14.46): Normal (Waiting) Interface intf2 (0.0.0.0): Normal (Shutdown) Interface intf3 (0.0.0.0): Normal (Shutdown) Interface intf4 (0.0.0.0): Normal (Shutdown) Other host: Secondary - Standby Active time: 0 (sec) Interface outside (x.y.9.10): Unknown (Waiting) Interface inside (x.y.14.45): Unknown (Waiting) Interface intf2 (0.0.0.0): Unknown (Shutdown) Interface intf3 (0.0.0.0): Unknown (Shutdown) Interface intf4 (0.0.0.0): Unknown (Shutdown)

Stateful Failover Logical Update Statistics Link : Unconfigured.

LAN-based Failover is Active interface LANFAIL (192.168.80.1): Normal, peer (192.168.80.2): Unknown

Reply to
Tom Pouce
Loading thread data ...

What does "show version" tell you? Are you on the FO box? You might need to change the console to the other PIX

Reply to
gwrowe

Also, I believe you need a third link for lan based FO.

Reply to
gwrowe

This is the output of the primary PIX. I used interface ethernet5 for the failover link

Reply to
Tom Pouce

looks like you do not have layer-2 connection between the two FO interfaces. To help out more, please also post the interface and failover part of your config.

You need to have a switch inbetween, and not just a crossover UTP. Also it might be because of the failover IP you have issued. Alternatively, you can enable debug, and manually active failover and watch the output. (type failover active on the primary host)

HTH Martin

Reply to
Martin Bilgrav

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.