FWSM Failover Help

Unanswered Question
Oct 27th, 2009
User Badges:

First time configuring the FWSM. I come from the days where firewalls were actually appliances. I know, so 2007!

I am having trouble following the nice 700 page guide on the FWSM. I am going through the chapter on Configuring Failover.

I ran into an error when configuring the faolover lan interface.

Here is what I want to do and hopefully you can walk me through this.

I have a server that will be plugged into VLAN 100 on port 6/1 on my CoreA 6513 and CoreB 6513. He will be bonded active/passive. I want him to use a default gateway of

I need the FWSM to present the ip address to the server on both the FWSMs. In the olden days (prior to FWSM) I would put an IP of and a standby of on CoreA and an IP of and a standby of on CoreB to make this happen.

On both FWSM I have created interface VLAN 100 with name TrafficCtrlA. On FWSM A I put IP standby and on FWSM B I put IP standby

I can add the failover lan unit primary command but then when I add the failover lan interface (if_name) vlan (vlan) part, I get an error that says the interface already exists. Of course it does! I just added it!

Not sure what to do with that.

Help? Please!


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Yudong Wu Tue, 10/27/2009 - 14:09
User Badges:
  • Gold, 750 points or more

On both FWSM A and B, you need configure the IP address of TrafficCtrlA as

ip address standby Yes, both have the same config.

Therefore, whoever is active will use IP and the other (standby) will use

If TrafficCtr1A is used as server's gateway, it's a normal interface and could not be used as failover link. Here is what doc says "The failover link uses a special VLAN interface that you do not configure as a normal networking interface;"

Please follow the config guide for more detail info.


jfraasch Wed, 10/28/2009 - 05:23
User Badges:

Thanks. That actually is beginning to make sense. I will test later today.


This Discussion