SonicOS 8 High Availability

Table of Contents

Configuring Active/Active DPI High Availability Settings

The configuration tasks on Device | High Availability > Settings are performed on the primary firewall and then are automatically synchronized to the secondary firewall.

To configure Active/Active DPI

  1. Navigate to Device | High Availability > Settings.
  2. In General Settings section, do the following:
    1. Select Active/Active DPI from the Mode drop-down field. A message about license and signature updates displays.
    2. Click OK.

      The Enable Stateful Synchronization is automatically enabled for Active/Active DPI, and the option is dimmed.

    3. (Optional) Ensure Enable Preempt Mode is not selected. This option is not selected by default.

      Preempt Mode should be disabled for Active/Active DPI. This option instructs the Primary firewall to take back the Primary role when it restarts after a failure; thus, this option only applies to Active/Standby configurations.

    4. (Optional) Select Enable Virtual MAC to allow both Primary and Secondary firewalls to share a single MAC address. This greatly simplifies the process of updating network ARP tables and caches when a failover occurs. This option is not selected by default.

      Only the switch to which the two firewalls are connected needs to be notified. All outside devices continue to route to the single shared MAC address.

    5. (Optional) Select Enable Encryption for Control Communication to encrypt HA control communication between the active and standby firewalls. This option is not selected by default.

      Firewall performance may be affected if you choose encryption.

      A confirmation message displays:

    6. Click OK

  3. In the HA Devices section, enter the Serial Number of the Secondary Device.

    The serial number for the Primary Device is displayed, but the field is dimmed and cannot be edited.

  4. In the HA Interfaces section:
    1. Select the interface for the HA Control Interface.

      This option is dimmed, and the interface is displayed if the firewall detects that the interface is already configured.

    2. Select the interface for the HA Data Interface.

      This option is dimmed, and the interface is displayed if the Security Appliance detects that the interface is already configured.

    3. Select the interface number for the Active/Active DPI Interface.

      This option is dimmed, and the interface is displayed if the Security Appliance detects that the interface is already configured.

      This interface is used for transferring data between the two Security Appliances during Active/Active DPI processing. Only unassigned, available interfaces appear in the drop-down menu. The connected interfaces must be the same number on both Security Appliances, and must initially appear as unused or unassigned interfaces in Network | Interfaces. For example, you can connect X5 on the Primary unit to X5 on the Secondary if X5 is an unassigned interface. After enabling Active/Active DPI, the connected interface has a zone assignment of HA Data-Link.

    4. Click Accept to complete the High Availability configuration.

      All settings are synchronized to the secondary security appliance and and the Secondary firewall reboots.