There isn't, although it is being worked on. The issue is that failover doesn't work with different versions of SW on the two PIX's, so if you're upgrading them then there has to be a point where they're swapped over from one to the other, unfortunately this requires a small outage.
But it's triky somehow. And you need to have console connection to both boxes.
The problem resides from the fact pix can't check if image was uploaded without any error.
Thats why Cisco recomands to have one box up&running.
And this means a short downtime.
I found another method: upload the image on both boxes; reload secondary; as soon as you see the secondary up reload the primary. If you don't do this very quick (1-2secs) you will get a lot of messages saying "mate run different software version" (something like that) and the failover will be disabled. But if you act quick you will not get any error and failover will remain enable.
The downtime is about 2-3 seconds - as soon as secondary box detect it is without primary and start building xlates and pass traffic.
When primary is up you can do a failover active to make primary box to be primary ;-) - but this is optional.
I did this few times and didn't had any problem.
You need to remember that despite this works perfect, Cisco doesn't offer support for.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :