×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

User cannot get secondary PIX Firewall to sync with the primary and no IP address is assigned to the secondary interfaces

Document

Wed, 07/22/2009 - 19:33
Jun 18th, 2009
User Badges:
  • Gold, 750 points or more

Core issue

The primary PIX Firewall shows the interfaces on the secondary PIX with an IP address of 127.0.0.1. The configuration does not have failover ip address commands.


Resolution

To resolve this issue, an IP address must be assigned to each interface on both the primary and secondary PIX Firewall.


To assign IP addresses to the interfaces of the secondary PIX Firewall, issue the failover ip address if_name ip_addr command.

Note: This command must be issued from the active PIX Firewall.

This is an example of this command:

failover ip address outside 192.168.1.2

failover ip address inside 10.10.10.2

failover ip address intf2 172.16.1.2

For more information on configuring failover, refer to Using PIX Firewall Failover.


PIX Software Version

PIX version 5.0

PIX version 6.3

PIX version 5.1

PIX version 5.2

PIX version 5.3

PIX version 6.0

PIX version 6.1

PIX version 6.2

Loading.

Actions

This Document

Related Content