
10-21
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Monitoring Failover
Failover Off
...
To disable the LAN failover link, disable failover and then disable the LAN failover link:
primary(config)# no failover
primary(config)# no failover lan enable
When you enable failover again, the firewall uses the serial failover cable if connected.
Monitoring Failover
When a failover occurs, both PIX Firewalls send out syslog messages, and the ACTIVE light on the front
of the devices indicate the current state. This section includes the following topics:
• Failover Syslog Messages, page 10-21
• SNMP, page 10-21
• Debugging Command, page 10-21
• ACTIVE Light, page 10-21
Failover Syslog Messages
The PIX Firewall issues a number of syslog messages related to failover at priority level 2, which
indicates a critical condition. To view these messages, see the Cisco PIX Firewall System Log Messages
to enable logging and to see descriptions of the syslog messages. If you search for “failover” on the
following web page, you can easily find related messages:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63syslog/pixemsgs.htm
SNMP
To receive SNMP syslog traps for failover, configure the SNMP agent to send SNMP traps to SNMP
management stations, define a syslog host, and compile the Cisco syslog MIB into your SNMP
management station. See the snmp-server and logging command in the Cisco PIX
Firewall Command
Reference for more information.
Debugging Command
To see debugging messages, enter the debug fover command. See the Cisco PIX Firewall Command
Reference for more information, or see the following URL:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/df.htm#94643
ACTIVE Light
The ACTIVE light on the front of the firewall indicates the unit’s failover state, either active (light is on)
or standby (light is off). If you do not enable failover, the ACTIVE light remains on.
Comentários a estes Manuais