PIX Stateful Failover Question

From: Andre Dufour (andremd4@gmail.com)
Date: Tue Mar 20 2007 - 10:17:04 ART


Hello,

I have a quick question. Why would a company not want to have stateful
failover implemented? What would be some reasons or risks of enabling
stateful-based failover? Take a look at the below exampe of a set of PIX
535s. Any info would be greatly appreciated. They have the additional
interfaces to do this.

Regards,
Andre

xxxxxxxxxxxx# show fail
Failover On
Cable status: Normal
Reconnect timeout 0:00:00
Poll frequency 3 seconds
Last Failover at: 08:55:14 ESDT Sun Mar 18 2007
        This host: Secondary - Active
                Active time: 173955 (sec)
                Interface syslog (10.x.x.x): Normal
                Interface intf2 (0.0.0.0): Link Down (Shutdown)
                Interface inside (192.168.x.x): Normal
                Interface outside (192.168.x.x): Normal
        Other host: Primary - Standby
                Active time: 798 (sec)
                Interface syslog (10.x.x.x): Normal
                Interface intf2 (0.0.0.0): Link Down (Shutdown)
                Interface inside (192.168.x.x): Normal
                Interface outside (192.168.x.x): Normal

*Stateful Failover Logical Update Statistics
        Link : Unconfigured.*



This archive was generated by hypermail 2.1.4 : Sun Apr 01 2007 - 06:35:52 ART