Providing firewall failover capabilities involves several basic hardware and software requirements. The firewalls must have the following:
When configuring for failover, firewall models need to be exactly the same all the way down to their memory sizes.
The PIX firewalls need to have the same hardware models for failover to work properly, but failover support is not available on all models. The 501, 506, and 506E do not support failover functionality; only the 515 and above models do.
Software on the two firewalls also needs to be the same version number; otherwise , failover might not work properly.
Every model of the PIX firewall, including the 501, uses the same software ”activation keys just enable extra features within the software. However, you still cannot use failover on the lower models.
Activations keys also need to be installed to enable the failover functionality of the software. Cisco has several licensing features for failover, as listed in Table 11.1.
Table 11.1. Licenses
Now that you have seen the various licenses available, Table 11.2 displays the possible primary and secondary licensing combinations.
Table 11.2. Licensing Combinations