Swapping out a hardware firewall does the mac address get cached?

Posted by Dan on Server Fault See other posts from Server Fault or by Dan
Published on 2010-12-30T05:36:31Z Indexed on 2010/12/30 6:55 UTC
Read the original article Hit count: 278

Filed under:
|
|

We need to replace a hardware firewall (cisco pix) and have a spare that we will use (temporarily). The firewall sits in front of a couple of web-servers colocated at a data-centre.

The replacement will be configured with identical settings (external/internal IP addresses, configured ports etc.).

When we swap the firewalls over, will this work immediately or will the old Pix's mac address be cached and the new firewall not be seen until the cache is cleared? (What is it though that is caching the address? Is it just the switch/router that our pix is connected to?)

Reason for asking is a few years ago I had a smoothwall firewall in front of a lone server (the external IP of the smoothwall was also the external IP of the web-server). When I replaced the smoothwall with a pix, the IP address of the web-server stayed the same but it now had to be reached via the new firewall on a different IP. It took about 2-4 hours before the rest of the world could see that web-server again. I'm hoping for less downtime this time!

© Server Fault or respective owner

Related posts about firewall

Related posts about pix