i'm testing failover with transparent mode and it seems to work fine when the active box goes down.
but i've been wondering if a 'monitor-interface' scenario is supposed to work with transparent mode. i actually tested this and it doesn't.
what i would like to happen is that if i have an active/standby pix scenario in transparent mode; when i disconnect (say) the outside interface, the active pix detects the 'link down'. i was hoping this would cause a failover event from active to standby, but it doesn't.
i'm aware that a monitor-interface scenario is somewhat L3 based, so a pix routed mode comes in handy. but i've been trying to get this to work and the active pix, just won't failover when in transparent mode.
my config only has the the basic failover commands and monitor interface commands. please keep in mind that in routed mode, failover works properly. i'm particularly interested in failover caused by an interface going down, instead of the whole active pix.
here's the config, thanks a lot!
description LAN/STATE Failover Interface
boot system flash:/pix702.bin
ftp mode passive
access-list inside extended permit ip any any
access-list outside extended permit ip any any
pager lines 24
mtu outside 1500
mtu inside 1500
ip address 10.0.0.3 255.255.255.0
failover lan unit primary
failover lan interface folink Ethernet2
failover polltime interface 3
failover interface-policy 50%
failover link folink Ethernet2
failover interface ip folink 10.0.1.1 255.255.255.0 standby 10.0.1.2
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...