I have a Active/Passive (Primary/Standby) Dual Firewall configuration into which I need to install a new PIX-1FE module. I already have a PIX-4FE in the unit with two available slots. Believe it or not I'm currently using all 6 of the interfaces and need one (1) more!
My questions are as follows:
1. What is the easiest way to upgrade this configuration? Break the failover cable, install the card in the standby unit, verify operation, down the primary unit, make the standby active, and repeat procedure for the primary unit?
2. Can I have a PIX-4FE & PIX-1FE in the same chassis? What are the slots I need to install into? (I think it makes a big difference where you put the new card!)
3. Do I have enough memory to handle both cards? I'm currently running around 250 Meg available on average (normal usage. During backups it's higher!)
4. What is the best way to get into the chassis? Mine is rack mounted and most likely will be a bear to get at (isn't that always the case?)
Here's what I've got for equipment:
Cisco PIX Firewall Version 6.1(1)
Hardware: PIX-525, 256 MB RAM, CPU Pentium III 600 MHz
Flash E28F128J3 @ 0x300, 16MB
BIOS Flash AM29F400B @ 0xfffd8000, 32KB
0: ethernet0: address is 0007.xxxx.xxxx, irq 10
1: ethernet1: address is 0007.xxxx.xxxx, irq 11
2: ethernet2: address is 00e0.xxxx.xxxx, irq 11
3: ethernet3: address is 00e0.xxxx.xxxx, irq 10
4: ethernet4: address is 00e0.xxxx.xxxx, irq 9
5: ethernet5: address is 00e0.xxxx.xxxx, irq 5
Maximum Interfaces: 8
Cut-through Proxy: Enabled
Inside Hosts: Unlimited
ISAKMP peers: Unlimited
Any comments/suggestions would be greatly appreciated.
1. - Power off Primary, disconnect all cables and take off-line. Slide out the internals of the box. (chasis can remain rack mounted). Insert in new 1FE card. Slide back in chasis, power up and verify card is recognized. If card is added to last slot, then no changes will be made to the config, except for new interface appearing. Power off, and reconnect all cables. Power off Secondary, then power ON primary. repeat above on Secondary. Once secondary is done, power off, plug in all cables and then power on. You're done.
2. Yes, any slot will work, just make sure you install it in the same slot on both chasis.
4. unscrew screws on back of box, and slide out the internals. Chasis case remains attached to rack.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :