[c-nsp] IOS Firewall sessions

Brian Stiff (bstiff) bstiff at cisco.com
Fri May 26 11:58:55 EDT 2006


 

> I have a question regarding IOS CBAC.
> Is there a way to sync the ip inspect session between two router, when
> both are configured as a firewall ?

IOS Version 12.4(6)T introduced active/standby stateful failover on the
3700, 3800, and 7200.  Docs are here:

http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0
0806106ea.html

Use cases are fairly limited due to the functional limitations of the
feature.  The Command Reference is the only documentation available for
the feature.

IOS Firewall Failover does not allow asymmetric routing, active/active
capability or load balancing.  It only supports failover on
single-channel TCP connections and UDP sessions.

Please unicast me if you would like to discuss this feature in greater
detail.

Regards,
Brian


Brian Stiff
IOS Firewall Technical Marketing Engineer
Cisco Systems



More information about the cisco-nsp mailing list