To configure advanced settings
The settings can be configured only on the active node. The standby node operates in readonly mode.
Navigate to Device | High Availability > Advanced.
In the Heartbeat Interval (milliseconds) field, specify how frequently the firewalls in the Active/Active DPI devices exchange heartbeat messages. This setting applies across all units in the cluster and helps determine cluster health and responsiveness.
Default: 1,000 milliseconds (1 second)
Range: 1,000–300,000 milliseconds
Use higher intervals in high‑traffic environments to reduce processing overhead. Lower intervals may increase sensitivity and can result in unnecessary failovers during periods of heavy load. This timer works in conjunction with the Failover Trigger Level (missed heartbeats).
In the Failover Trigger Level (missed heartbeats) field, define how many consecutive heartbeats can be missed before initiating a failover. This value applies to all units within the Active/Active DPI devices.
This setting works together with the Heartbeat Interval timer. For example, if the Failover Trigger Level is set to 5 and the Heartbeat Interval is 10,000 milliseconds (10 seconds), the system waits 50 seconds without receiving a heartbeat before triggering failover.
Default: 5
Range: 4–99
In the Probe Interval (seconds) field, enter the number of seconds between probes sent to the specified IP address(es) to verify that the network’s critical path remains reachable. This interval is used in logical monitoring for the local HA pair.
Default: 20 seconds
Range: 5–255 seconds
Default: 3
Range: 3–10
In the Election Delay Time (seconds) field, specify how long the active appliance waits before considering an interface “up” and stable. It is useful when switch ports have spanning‑tree delays
Default: 3 seconds
Range: 3–255 seconds
In the Dynamic Route Hold-Down Time (seconds) field, enter the duration for which the newly active appliance retains old dynamic routing entries after failover. This allows time to relearn routes from dynamic routing protocols (RIP, OSPF, BGP) before replacing old entries.
Default: 45 seconds
Range: 0–1200 seconds (20 minutes)
The Dynamic Route Hold-Down Time setting is displayed only when the Advanced Routing Mode option is selected on Network | System > Dynamic Routing > Settings.
In large or complex networks, a larger value may improve network stability during a failover.
This setting is used when a failover occurs on a High Availability pair that is using either a dynamic routing protocol. During this time, the newly-active appliance relearns the dynamic routes in the network. When the dynamic route hold-down time duration expires, SonicOS deletes the old routes and implements the new routes it has learned from routing protocols.
In the SD‑WAN Probes Hold‑Down Time (seconds) field, specify how long SonicOS waits before restoring a previously failed WAN path back to an active/available state.
Default: 60%
Range: 0-100%
SonicOS shifts this percentage of DPI tasks to the secondary appliance to balance processing load.
Default: 60%
This threshold can be manually tuned to adjust how aggressively DPI is redistributed.
(Optional) To force synchronize the SonicOS preference settings between your primary and secondary HA firewalls, click Synchronize Settings.
All settings are synchronized to the Secondary Security Appliance.