cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
0
Helpful
5
Replies

PIX Failover vs. Load Balancing with CSS

mromer
Level 1
Level 1

Is there, anywhere, some document that compares/contrasts setting up two PIX's in failover mode versus load balancing them as discussed in this document?

http://www.cisco.com/en/US/customer/products/hw/contnetw/ps789/products_configuration_example09186a008009438c.shtml

I'm trying to figure out the benefits of doing the load-balanced configuration and weigh them against the cost of the CSS's.

Thank you.

-Mark Romer

5 Replies 5

nkhawaja
Cisco Employee
Cisco Employee

Hi,

Load balancing with firewall will/may not work and is not a good idea. Firewalls behaviour is statefull inspection so if a packet leaves from one firewall and enters other , it will get discarded.

Failover PIXen is for redundancy and high availability as you already aware.

Thanks,

Thanks for the reply.

The CSS's on either side of the firewalls maintain a flow for each connection, ensuring that all traffic within a TCP session travels through the same firewall.

We are using this load balancing configuration for our production web farm. What I'm trying to figure out is what we might lose if we reconfigured the two PIXs for failover and used a couple of the CSS's elsewhere.

-Mark

Mark,

As you have seen load balancing PIX's with the CSS's does work and we have many customers doing it. Your question, however is difficult to answer. As I am sure you know, the idea with load balancing the PIX's is too split the load across 2 seperate platforms. Failover and load balancing in the PIX's is going to be quite different. If you moved to a failover setup and config'ed stateful failover as well, you would gain the ability to maintain "state" if one of the firewalls went down. Meaning, sessions that were open through the active firewall would be replicated over to the stand-by firewall so when the failover ooccured, the end user would not necessarily know. I do not think you would currently have this ability in the load balanced setup. Of course, the biggest concern you are going to need to take a look at is whether one PIX can currently handle that load that you have 2 PIX's handling now. The biggest concern would probably be the connections. You can issue a 'sh conn count' to get a rough idea of how many conns wach PIX has at the time the command is run. Summing these numbers and comparing it to the numbers we provide for max conns on your platform can give you a rough idea of what to expect.

I know this is not the concrete answer you were looking for but hopefully it gives you some ideas on where to start. Good luck.

Scott

Thanks, Scott. That gives me a direction to look in, at least.

-Mark

Does anyone load-balancing PIXs with Alteon switches ?

Best Regards,

Engel

Review Cisco Networking products for a $25 gift card