PIX525: Need Failover help

Hi everyone,

My PIX525 (running PIX 7.1(2)) currently has the failover serial cable connected as well as a cross-over cable connected to a 10/100 port (LAN failover is not currently enabled though). I've had a couple of unexpected failovers happen, and when these happen, we lose connection. This has made me want to go ahead and enable LAN failover so as to be able to take advantage of not having those network hiccups during failovers. The issue is that I actually have gig ports on this FW, but the failover is set up on a

10/100 port. I understand that it is recommended to have the LAN failover on the fastest port.

The situation with the 2 gig ports I have (both are fiber connected) is that Gigport0 is configured as the "inside" interface with no sub interfaces. Gigport1 is also enabled, and with 7 subinterfaces. I've heard that it is also recommended to dedicate a port to failover rather than having any subinterfaces sharing it (is that true?). Note than the "inside" network consists of about 10 VLANs... and lots of traffic.

My idea is to move the "inside" interface to Gigport1 as a subinterface thereby freeing up Gigport0 to be used exclusively as the failover port. Does this plan seem like a good idea? Is there anything I should watch out for? The fiber cable connecting the gig ports are connected to switches... would it still work given that primary and secondary PIXs won't be directly connected to each other? Also, what if I just enable LAN failover leaving it on the 10/100 port?

Any advice would be greatly appreciated. Thanks!

Kevin

Reply to
Jon Doe
Loading thread data ...

Anyone?

Reply to
Jon Doe

where is this need for a "fast" port documented? i only remember C$ saying they recommend 100/full for the stateful failover interface. try completely configuring failover on all interfaces and see what happens... having the serial cable connected and not having failover configured might upset the PIX. PIX OS 7.x does things much differently then 6.x. also make sure your speed and duplex are set correctly (disable autoneg). i have 8 PIX 525's using the serial port failover cable with 100 meg failover interfaces and never had a problem. if your PIXen are right next to each other why not use the serial cable? LAN based failover is more helpful in a scenario where the PIXen are not even close to each other.

that's fine. it's recommended to have failover interface on a dedicated interface, like copper. use those useless 10/100 meg ports.

why waste your fiber gig ports on failover? that's obscene! your fiber ports should all be connected to a 802.1q trunk port. then config each subinterface to be monitored. the subifs are in the same vlan for both PIXen, so in theory they are connected.

Reply to
uNiXpSyChO

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.