10-17-2006 10:48 PM - edited 03-09-2019 04:34 PM
Is it possible to implement redundant ISP's with failover firewalls using virtual interfaces and the ISP connetions? I have a 5520 with the standard number of interfaces and want to create virtual interfaces on the outisde interface?
10-18-2006 01:02 PM
When you say virtual interfaces are you talking about sub interfaces?
These can each be a different vlan and can be monitored for failover etc...
10-18-2006 01:54 PM
You may create a sub-interface on the outside interface and use it as a backup interface. Here is a sample config :
Please rate if it helps.
Sincerely,
~AJ
10-20-2006 05:53 AM
The interface tracking in that version brakes when using a failover pair. The tracking works until failover occurs. Then a reboot of both firewalls is required to fix the tracking.
Bug: CSCsd51407
Dual ISP fails after failover, routing table have stale routes
A new release is coming soon to fix the bug. 7.2(1) is the only version out that supports tracking.
Thanks,
Chad
11-07-2006 07:49 AM
looks like they fixed the bug in ver 7.2.1.24 on the 10/30/2006
bug id CSCse99033
http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCse99033&Submit=Search
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: