RE: [nsp] REG: PIX Failover Bundle.

From: Vinod Anthony Joseph Cherunni (vac@dsqworld.com)
Date: Mon Apr 23 2001 - 07:10:16 EDT


Dear All,

My sincere thanks for all the valuble advice. As indicated by Mr. Ian in
the given below -

In this scenario you have and outside interface on PIX #1 with an address
of x.x.x.1 and a failover address for the outside interface of x.x.x.2 -
This .2 address becomes the address for the outside interface on PIX #2.
You will need to assign different IP's as mentioned above.

If I define the inside interface on PIX #1 with an address of y.y.y.1 and a
failover address for the outside interface of y.y.y.2. How will I configure
say a Win-NT ftp client PC connecting to an Internet host with a default
gateway. In normal circumstances I would prefer to have such client PC's &
servers of mine on the inside network point to a single default gateway.
Typically Cisco routers with two ethernet ports configured to build port
level redundancy are configured with techniques such as IRB, &
Backup-interface. Is there something similar here, wherein I don't need to
define more than one gateway address on all my client systems. Or else does
the failover PIX do a some kind of Proxy ARP the moment a port on the
Active unit fails.

In regard to disabling NAT on the PIX, Will the following work. Kindly
correct me if I am wrong.

nat (inside) 0 0.0.0.0 0.0.0.0 - To disable NAT.

Kindly enlighten me.

With warm regards,
Vinod.



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:35 EDT