Basic Features of PIX Firewall: failure handling Mechanism and redundancy-principles and experiments
(1) terminology
(2) basic process
Step 1: the active unit copies all its configurations to the standby unit and commands are sent over the failure handling mechanism cable
Step 2: sends a dedicated Hello packet every 15 seconds
Step 3: the standby unit does not receive two consecutive Hello packets within a specified time
Step 4: transfer activity control to the standby unit, while the failure handling mechanism tests the interface through various tests
(3) experiment
Note: import the activation code on the PIX firewall before doing this lab
Here R2 is the Internet.
Step 1: R1 and R2 configuration (brief)
Step 2: FW1 configuration to access Internet
Step 3: FW1-Failover configuration
Step 4: FW2-Failover configuration
Step 1: R1 and R2 configuration (brief)
Step 2: FW1 configuration to access Internet
Interface configuration:
FW1 (config) # interface e0
FW1 (config-if) # no shutdown
FW1 (config-if) # ip add 192.168.1.254 255.255.255.0
FW1 (config-if) # nameif inside
FW1 (config-if) # security-level 100
FW1 (config) # interface E1
FW1 (config-if) # no shutdown
FW1 (config-if) # ip add 100.1.1.1 255.255.255.0
FW1 (config-if) # nameif outside
FW1 (config-if) # security-level 100
FW1 (config) # interface e2
FW1 (config-if) # no shutdown
FW1 (config-if) # ip add 10.1.12.1 255.255.255.0
FW1 (config) # interface E3
FW1 (config-if) # no shutdown
FW1 (config-if) # ip add 10.2.12.1 255.255.255.0
Default route, NAT configuration
FW1 (config) # route outside 00 100.1.1.2
FW1 (config) # access-list NAT permit ip any any
FW1 (config) # nat (inside) 1 access-list NAT
FW1 (config) # global (outside) 1 interface
Step 3: FW1-Failover configuration
FW1 (config) # failover / / enable failure handling
FW1 (config) # failover lan enable / / enable LAN-based failure handling
FW1 (config) # failover key cisco / / Certification of account failure handling function
FW1 (config) # failover lan unit primary / / set as the active unit
FW1 (config) # failover lan interface PZ Ethernet2 / / name the e2 interface PZ and define it as the configuration interface
FW1 (config) # failover lan link ZT Ethernet3 / / name the E3 interface ZT and define it as a stateful interface
FW1 (config) # failover interface ip PZ 10.1.12.1 255.255.255.0 standby 10.1.12.2 / / specify the primary and secondary configuration interfaces, and configure the IP address for the primary configuration interface
FW2 (config) # failover interface ip ZT 10.2.12.1 255.255.255.0 standby 10.2.12.2 / / specify the primary and secondary state interfaces
Step 4: FW2-Failover configuration
Basic interface configuration:
FW2 (config) # interface e0
FW2 (config) # no shudown
FW2 (config) # interface E1
FW2 (config) # no shutdown
FW2 (config) # interface e2
FW2 (config) # no shutdown
FW2 (config-if) # ip address 10.1.12.2 255.255.255.0
FW2 (config) # interface E3
FW2 (config) # no shutdown
FW2 (config) # ip address 10.2.12.2 255.255.255.0
Failover configuration:
FW1 (config) # failover / / enable failure handling
FW1 (config) # failover lan enable / / enable LAN-based failure handling
FW1 (config) # failover key cisco / / Certification of account failure handling function
FW1 (config) # failover lan unit secondary / / set as standby unit
FW1 (config) # failover lan interface PZ Ethernet2 / / name the e2 interface PZ and define it as the configuration interface
FW1 (config) # failover lan link ZT Ethernet3 / / name the E3 interface ZT and define it as a stateful interface
FW1 (config) # failover interface ip PZ 10.1.12.1 255.255.255.0 standby 10.1.12.2 / / specify primary and secondary configuration interfaces
FW2 (config) # failover interface ip ZT 10.2.12.1 255.255.255.0 standby 10.2.12.2 / / specify the primary and secondary state interfaces