SonicOS 8 High Availability

Table of Contents

Crash Detection

The HA feature has a thorough self-diagnostic mechanism for both the Active and Standby Security Appliances. The failover to the standby unit occurs when critical services are affected, physical or logical link failure is detected on monitored interfaces, or when the Security Appliance loses power.

The self-checking mechanism is managed by software diagnostics, which check the complete system integrity of the Security Appliance. The diagnostics check internal system statuses, system process statuses, and network connectivity. There is a weighting mechanism on both sides to decide which side has better connectivity to avoid potential failover looping.

Critical internal system processes such as NAT, VPN, and DHCP (among others) are checked in real time. The failing service is isolated as early as possible, and the failover mechanism repairs it automatically.

In Active/Active DPI mode, crash detection continuously monitors the health and availability of both appliances participating in traffic and DPI processing. In addition to standard system, process, and link monitoring, the HA subsystem verifies the availability of DPI offload communication paths between the two units to ensure uninterrupted inspection services.

If the appliance responsible for DPI offload processing experiences a critical failure—such as a system crash, loss of monitored interfaces, or loss of inter‑appliance communication—the HA mechanism immediately halts DPI offloading and transitions the system into a single‑unit Active/Standby behavior.