RE: [nsp] REG: PIX Failover Bundle.

From: Vinod Anthony Joseph Cherunni (vac@dsqworld.com)
Date: Mon Apr 23 2001 - 07:55:54 EDT


Dear All,

My sincere thanks for all the valuble advice. As indicated by Mr. Ian in
the given below -

In this scenario you have and outside interface on PIX #1 with an address
of x.x.x.1 and a failover address for the outside interface of x.x.x.2 -
This .2 address becomes the address for the outside interface on PIX #2.
You will need to assign different IP's as mentioned above.

If I define the inside interface on PIX #1 with an address of y.y.y.1 and
a failover address for the outside interface of y.y.y.2. How will I
configure say a Win-NT ftp client PC connecting to an Internet host with a
default gateway. In normal circumstances I would prefer to have such
client PC's & servers of mine on the inside network point to a single
default gateway. Typically Cisco routers with two ethernet ports
configured to build port level redundancy are configured with techniques
such as IRB, & Backup-interface. Is there something similar here, wherein
I don't need to define more than one gateway address on all my client
systems. Or else does the failover PIX do a some kind of Proxy ARP the
moment a port on the Active unit fails.

In regard to disabling NAT on the PIX, Will the following work. Kindly
correct me if I am wrong.

nat (inside) 0 0.0.0.0 0.0.0.0 - To disable NAT.

Kindly enlighten me.

With warm regards,
Vinod.



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:35 EDT