wrote:
>Does failover work if two PIX are connected via one or more routers
>(say on internal interfaces in high availability configurations for
>example) or is it mandatory to have layer 2 links between the two
>firewalls?
>
>Thank you
Even though you assign IP addresses to the fialovers (which might make
you think they could withstand layer 3 routing), i think the timeout
tolerances are VERY low (milliseconds definitely <1 second). I found
a dumb setup on a pix where one side of the pix backhauled through
media converters to a switch in a different building. So the heartbeat
had to hop through 2 media convertors ride fiber back to another
building (a football field away)go through a switch to ride fiber and
2 more media convertors back to the original building to get to the
fialover's twin interface. every 20 to 40 seconds we had an interface
failure, which recovered the next second(when it re-attempted). That
was layer 2, but the delays were enough to cause a problem.
DiGiTAL_ViNYL (no email)