49-11
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter4 9 Configuring Failover
Failover Policies
Field Reference
Edit Failover Interface Configuration Dialog Box (PIX 6.3)
Use the Edit Failover Interface Configuration dialog box to configure failover interfaces for the selected
PIX 6.3.x device.
Table49-1 Failover Page (PIX 6.3)
Element Description
Failover
Failover Method Choose the type of failover link: Serial Cable or LAN Based. If you
choose Serial Cable, ensure the physical cable is connected to both
devices.
Enable Failover Check this box to enable failover on this device. Ensure that both
devices have the same software version, activation key type, flash
memory, and RAM.
On PIX devices with LAN Based chosen as the Failover Method, you
must next configure the logical LAN Failover interface and, optionally,
the stateful failover interface.
Bootstrap button Click to display the Bootstrap Configuration for LAN Failover dialog
box. See Bootstrap Configuration for LAN Failover Dialog Box,
page 49-26 for more information.
Failover Poll Time Specify the amount of time between hello messages among units.
Values can range from 3 to 15 seconds; default is 15.
LAN-Based Failover
These fields are available when LAN Based is the chosen Failover Method.
Interface Choose the interface to be used for LAN-based failover. If “Not
Selected” is chosen, LAN-based failover is disabled.
Shared Key
Confirm
Used to encrypt communications between the primary and standby
devices. Value can be any alphanumeric string.
Re-enter the Shared Key in the Confirm field.
Stateful Failover
(Optional) To configure Stateful Failover, page 49-4, provide the following parameters.
Interface Choose the interface to be used for Stateful Failover. If “Not Selected”
is chosen, Stateful Failover is disabled.
Note You must choose a fast LAN link from the list (for example,
100full, 1000full, or 1000sxfull).
Enable HTTP Replication When selected, active HTTP sessions are copied to the standby firewall.
Otherwise, HTTP connections are disconnected at failover. Disabling
HTTP replication reduces the amount of traffic on the state link.
Interface Configuration
The table lists all available named interfaces. To define a Standby IP address and Active and Standby
MAC addresses for an interface, select it in the list and click the Edit Row button to open the Edit
Failover Interface Configuration Dialog Box (PIX 6.3), page 49-11.