Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

RE: Pix 515's fail to failover

Subject: RE: Pix 515's fail to failover
Date: Tue, 16 Nov 2004 01:38:27 +1100
Hey Spigga,

I'm going to pressume that having so many PIXes, you're more than offay with
configuring them. Have you tried to debug the problem? What messages are you
getting? If they aren't already, perhaps you could try taking a pair of the
PIXes out, putting them into a test environment with different switches and
starting with a fresh config, just to start a process-of-elimination.

I'm sure you'll have this already, but here's Cisco's link for the PIX 6.3
failover chapter:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration
_guide_chapter09186a008017278a.html

Regards,

Jason

 

-----Original Message-----
From: Spigga [mailto:spigga@gmail.com] 
Sent: Friday, 12 November 2004 9:56 AM
To: firewalls@securityfocus.com
Subject: Pix 515's fail to failover

I have 2 HA pairs that refuse to failover properly.  If the primary is
active, and I try to fail it over to standby, they both go standby and
traffic halts. I have to power cycle the primary and all is well. 
This is the same situation on two separate pairs one pair  running
6.3(3) and one running 6.3(4).  They both started doing this on the same
day.  One during failover testing and one pair just stopped passing traffic
and never failed over so we had a guy power off the primary and since then
failover does not work.  In one case we replaced the primary and it still
happens.  We have replaced serial and lan failover cables.  Anyone seen or
heard of this?  We have close to 300 pixes, a large number runninf 6.3(3)
and some running 6.3(4) and no others are having trouble but we haven't
failed any over since this started.  I'm afraid to test.

Attachment: smime.p7s
Description: S/MIME cryptographic signature

<Prev in Thread] Current Thread [Next in Thread>