Swapping out a hardware firewall does the mac address get cached?
Posted
by
Dan
on Server Fault
See other posts from Server Fault
or by Dan
Published on 2010-12-30T05:36:31Z
Indexed on
2010/12/30
6:55 UTC
Read the original article
Hit count: 302
We need to replace a hardware firewall (cisco pix) and have a spare that we will use (temporarily). The firewall sits in front of a couple of web-servers colocated at a data-centre.
The replacement will be configured with identical settings (external/internal IP addresses, configured ports etc.).
When we swap the firewalls over, will this work immediately or will the old Pix's mac address be cached and the new firewall not be seen until the cache is cleared? (What is it though that is caching the address? Is it just the switch/router that our pix is connected to?)
Reason for asking is a few years ago I had a smoothwall firewall in front of a lone server (the external IP of the smoothwall was also the external IP of the web-server). When I replaced the smoothwall with a pix, the IP address of the web-server stayed the same but it now had to be reached via the new firewall on a different IP. It took about 2-4 hours before the rest of the world could see that web-server again. I'm hoping for less downtime this time!
© Server Fault or respective owner