SonicOS 8 High Availability

Table of Contents

Configuring Advanced High Availability Settings

To configure advanced settings

  1. Log in as an administrator to the SonicOS Management Interface on the Active Node.

    The settings can be configured only on the active node. The standby node operates in readonly mode.

  2. Navigate to Device | High Availability > Advanced.

  3. In the Heartbeat Interval (milliseconds) field, specify how frequently the firewalls in the Active/Active DPI devices exchange heartbeat messages. This setting applies across all units in the cluster and helps determine cluster health and responsiveness.

    • Default: 1,000 milliseconds (1 second)

    • Range: 1,000–300,000 milliseconds

    Use higher intervals in high‑traffic environments to reduce processing overhead. Lower intervals may increase sensitivity and can result in unnecessary failovers during periods of heavy load. This timer works in conjunction with the Failover Trigger Level (missed heartbeats).

  4. In the Failover Trigger Level (missed heartbeats) field, define how many consecutive heartbeats can be missed before initiating a failover. This value applies to all units within the Active/Active DPI devices.

    This setting works together with the Heartbeat Interval timer. For example, if the Failover Trigger Level is set to 5 and the Heartbeat Interval is 10,000 milliseconds (10 seconds), the system waits 50 seconds without receiving a heartbeat before triggering failover.

    • Default: 5

    • Range: 4–99

  5. In the Probe Interval (seconds) field, enter the number of seconds between probes sent to the specified IP address(es) to verify that the network’s critical path remains reachable. This interval is used in logical monitoring for the local HA pair.

    • Default: 20 seconds

    • Range: 5–255 seconds

  6. In the Probe Count field, specify how many consecutive missed probes must occur before SonicOS determines that the critical path or probe target is unreachable. This count is used in logical monitoring for the HA failover decisions.
    • Default: 3

    • Range: 3–10

  7. In the Election Delay Time (seconds) field, specify how long the active appliance waits before considering an interface “up” and stable. It is useful when switch ports have spanning‑tree delays

    • Default: 3 seconds

    • Range: 3–255 seconds

  8. In the Dynamic Route Hold-Down Time (seconds) field, enter the duration for which the newly active appliance retains old dynamic routing entries after failover. This allows time to relearn routes from dynamic routing protocols (RIP, OSPF, BGP) before replacing old entries.

    • Default: 45 seconds

    • Range: 0–1200 seconds (20 minutes)

    The Dynamic Route Hold-Down Time setting is displayed only when the Advanced Routing Mode option is selected on Network | System > Dynamic Routing > Settings.

    In large or complex networks, a larger value may improve network stability during a failover.

    This setting is used when a failover occurs on a High Availability pair that is using either a dynamic routing protocol. During this time, the newly-active appliance relearns the dynamic routes in the network. When the dynamic route hold-down time duration expires, SonicOS deletes the old routes and implements the new routes it has learned from routing protocols.

  9. In the SD‑WAN Probes Hold‑Down Time (seconds) field, specify how long SonicOS waits before restoring a previously failed WAN path back to an active/available state.

  10. Enable Active/Standby Failover only when ALL aggregate links are down field, if failover should occur only when ALL aggregate links are down. This option is not selected by default.
  11. Enable Include Certificates/Keys field to synchronize all certificates and keys within the HA pair. This option is selected by default.
  12. In the Active/Active DPI Traffic Offload % field, specify the percentage of total Deep Packet Inspection (DPI) traffic to be offloaded to the standby unit in an Active/Active DPI setup.
    • Default: 60%

    • Range: 0-100%

    SonicOS shifts this percentage of DPI tasks to the secondary appliance to balance processing load.

  13. In the Active/Active DPI CPU Threshold % field, specify the CPU utilization level on the primary appliance that triggers DPI offloading to the standby unit. When CPU usage hits this threshold, the system offloads DPI processing to prevent performance degradation.
    • Default: 60%

    This threshold can be manually tuned to adjust how aggressively DPI is redistributed.

  14. (Optional) To force synchronize the SonicOS preference settings between your primary and secondary HA firewalls, click Synchronize Settings.

  15. (Optional) Click Synchronize Firmware to synchronize the firmware version between your primary and secondary HA firewalls.
  16. (Optional) Click Force Active/Standby Failover to test the HA failover functionality is working properly by attempting an Active/Standby HA failover to the secondary Security Appliance.
  17. Click Accept to complete the High Availability configuration.

    All settings are synchronized to the Secondary Security Appliance.