Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


PIX Failover Feature

Feb 15,2010 by alperen

image

The firewall’s critical role in the network security design makes device failure of any kind a serious consideration. The failover feature allows an identical PIX firewall unit to provide redundancy if the primary unit fails. One unit is considered the “active” or “primary” unit, while the other is considered the “standby” or “secondary” unit. The active unit performs its normal network functions, while the standby unit only monitors the other unit, ready to take control if the active unit fails.

Since PIX OS v5.1, PIX models support stateful failover, allowing the system to maintain connection state information for the TCP connection during the failover from the primary unit to the standby unit. If failover occurs, the secondary unit assumes the IP and MAC addresses of the primary unit and begins accepting traffic. Because the other network devices don’t see any change in these addresses, no ARP entries change or timeouts occur anywhere in the network.


295 times read

Related news

» LAN-Based Failover Configuration
by alperen posted on Feb 15,2010
» Failover Configuration with Failover Cable
by alperen posted on Feb 15,2010
» Understanding Failover
by alperen posted on Feb 15,2010
» Managing and Maintaining the PIX Firewall Review
by alperen posted on Feb 19,2010
» Data transmission
by alperen posted on Mar 25,2010
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author