Failover Operations
Once two FWSMs are configured for failover, one will act as an active unit and the other one will act as standby. The decision-making process is dictated by the configuration and sequence of reboot. You can configure one of the units to be primary and other to be secondary. Prior to FWSM Version 2.x, FWSM worked in single firewall mode, but beginning with FWSM Version 2.x, a single FWSM can be converted to multiple virtual firewall (by configuring a security context). If you run failover in multiple mode, failover is not virtualized in release 2.x, which means that failover is not determined on a per-context basis, but rather as a whole for the module. A single context cannot be active when another context is standby on the same FWSM; rather all contexts are either active or standby. During the initialization phase, active and standby roles are decided. It is, however, possible to change the role of failover manually after the initialization process.