RE: PIX with failover license

From: Kevin Minihane (kevin.minihane@eirteic.com)
Date: Thu Jan 27 2005 - 06:27:34 GMT-3


Hi

I'm wondering if the original question referred to using the failover
license without having a primary firewall in place in the first place? My
understanding is that you need to have some sort of primary PIX running,
with the failover connected in order to get the failover one working
initially. After that, if the primary one fails, (or if you remove it, and
leave the failover in place) the failover will work away, but can lock up
every now and again. Can anyone verify if this is, in fact, the way it is
designed?

Regards

Kevin

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of Rick
Sent: 27 January 2005 02:25
To: ccie@rivancitadel.com; Cisco certification
Subject: Re: PIX with failover license

What good is a failover device that locks up every so often? Sounds stupid
to me.

We have never had a PIX that failed over to lockup because it was running as
a FO license. We have had it fail back over for the same reason the
unrestricted failed over :-) something like 300,000 sessions when it is
suppose to support 500,000..........

One of our pair of PIX's is currently going on 48 days running on the FO
licensed PIX.. The UR licensed PIX is dead and we have been through 3 RMA's
trying to get it working again.

Rick

----- Original Message -----
From: <ccie@rivancitadel.com>
To: <ccielab@groupstudy.com>
Sent: Wednesday, January 26, 2005 10:27 AM
Subject: RE: PIX with failover license

> Hello,
>
> To clarify a little. You couldn't use the FO licensed PIX in a
> production environment. It will process a certain amount of data then lock
> up. You can use it in a Lab environment. You will just need to reboot
power
> cycle the PIX from time to time. That is what I have done with one in my
> lab. Hope this helps.
>
> Russ.
>
> -----Original Message-----
> From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
> Kevin Minihane
> Sent: Wednesday, January 26, 2005 11:16 AM
> To: 'Tom Young'
> Cc: ccielab@groupstudy.com
> Subject: RE: PIX with failover license
>
> Hi
>
> I ran into the same problem just last week. No, you cant (according to
> Cisco) run a PIX using only a failover licence. I managed to upgrade my
> licence to restricted software licence, and now everything is working
fine.
> This drove me nuts for a few weeks, until I got it sorted. My vendor
> shipped me the wrong licence, soI was in limbo for a while.
>
> Anyway, again, to answer your question, (and to repeat what a local Cisco
> engineer told me), you can't use the failoer licence on it's own
>
>
> Cheers
>
> Kevin
>
> -----Original Message-----
> From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Tom
> Young
> Sent: 26 January 2005 14:57
> To: ccielab@groupstudy.com
> Subject: PIX with failover license
>
> hi, group
>
> May I use a pix with FO license as a single firewall not for the
failover
> constrction.
> Could it do all the basic functions as a normal firewall?
>
> thanks
>
> __________________________________
> Let's Celebrate Together!
> Yahoo! JAPAN
> http://pr.mail.yahoo.co.jp/so2005/
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Wed Feb 02 2005 - 22:10:26 GMT-3