Hi,
I don't believe this is possible but I'm hoping someone can prove me wrong!
We want a dual PIX configuration for accessing the internet providing standard firewalling techniques including NAT. However, rather than configuring the PIX's in a failover configuration (i.e. one box sits doing nothing until something goes wrong with the main PIX) I was wondering whether we could configure resilience while incorporating load sharing across the two PIX's, i.e. both PIX's servicing packets but if one goes down the other continues servicing all the packets by itself.
The problem with this configuration is session management, syncronising the routing and NAT tables between the PIX's. Does anyone know if there is a way to achieve this?
Thanks.
I don't believe this is possible but I'm hoping someone can prove me wrong!
We want a dual PIX configuration for accessing the internet providing standard firewalling techniques including NAT. However, rather than configuring the PIX's in a failover configuration (i.e. one box sits doing nothing until something goes wrong with the main PIX) I was wondering whether we could configure resilience while incorporating load sharing across the two PIX's, i.e. both PIX's servicing packets but if one goes down the other continues servicing all the packets by itself.
The problem with this configuration is session management, syncronising the routing and NAT tables between the PIX's. Does anyone know if there is a way to achieve this?
Thanks.