We just bought a cisco pix 515 and it come with failover license. I would like to disable it because we dont have active or standby pix. This is the only pix we have. I am getting this error message. Configuration Replication is NOT performed from Standby unit to Active unit. Configurations are no longer synchronized.
The problem you have is that the pix you have bought has a failover license only. This pix is intended to be run as a pair. The primary pix will have an unrestricted license and the failover pix hs a failover license. A pix with a failover license was never intended to be run as a standalone pix.
Attached is a doc from Cisco outlining the differences in pix licenses.
Thanks Jon. I had to force it with the failover active command then it started to work but not for long and it to not respond. If I want to upgrade the license to unrestricted will cisco change me for this?
You will need to order on of the following license and loaded into your PIX in order to get the PIX working as you want.
PIX-515-SW-FO-R= (Restricted license)
PIX-515-SW-FO-UR= (Unrestricted license)
The following is straight from cisco.com
Restricted Software License
The Cisco PIX 515E Restricted (PIX 515E-R) model provides an excellent value for organizations looking for robust Cisco PIX Security Appliance services with minimal interface density and VPN throughput requirements. It includes 64 MB of RAM, two 10/100 Fast Ethernet interfaces, and support for one additional 10/100 Fast Ethernet interface.
Unrestricted Software License
The PIX 515E Unrestricted (PIX 515E-UR) model extends the capabilities of the family with support for stateful failover, additional LAN interfaces, and increased VPN throughput via integrated hardware-based VPN acceleration. It includes an integrated VAC or VAC+ hardware VPN accelerator, 128 MB of RAM, two 10/100 Fast Ethernet interfaces, and support for up to four additional 10/100 Fast Ethernet interfaces. The Cisco PIX 515E-UR also adds the ability to share state information with a secondary Cisco PIX Security Appliance (either in an Active/Active or Active/Standby deployment model) for resilient network protection.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :