Im running a pair of 535's in a failover pairing, the main interfaces are GB-ethernet (0 and 1) but the failover interface is a standard ethernet connection - WILL THIS BE AN ISSUE FOR A STATEFUL FAILOVER ???
Just a pointer - if there is reference to the access-list that you are removing anywhere else in the config - it will also be removed!!! (Found out during access-list ammending!!)
i.e nat statements, cryptomap statements etc.
The isakmp keystring has to be identical at both peers and can be any combination of letters (up to 128 bytes long).
The keystring is 'hashed out' in the config - so nobody can decrypt it after youve applied it - but it can be over written when you deem fit.
Yep, thats the correct line (but inc the line above as well - timeout xlate hh:mm:ss).
The timings you have stated are the default timings - they can be changed to suit your needs.
You may want to try extending the TCP half-closed timings - you can use 0:0:0 to never time out a half-closed...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.