SonicOS 8 High Availability

Table of Contents

High Availability Modes

High Availability has several operation modes, which can be selected on DEVICE | High Availability > Settings.

  • None - Selecting None activates a standard high availability configuration and hardware failover functionality, with the option of enabling Stateful HA.
  • Active/Standby - Active/Standby mode provides basic high availability with the configuration of two identical Security Appliances as a High Availability Pair. The Active unit handles all traffic, while the Standby unit shares its configuration settings and can take over at any time to provide continuous network connectivity if the Active unit stops working.

    By default, Active/Standby mode is stateless, meaning that network connections and VPN tunnels must be re-established after a failover. To avoid this, Stateful Synchronization can be licensed and enabled with Active/Standby mode. In this Stateful HA mode, the dynamic state is continuously synchronized between the Active and Standby units. When the Active unit encounters a fault condition, stateful failover occurs as the Standby Security Appliance takes over the Active role with no interruptions to the existing network connections.

    Stateful HA is:

    • Included on NSA 4600 and higher NSA platforms.
    • Supported on the NSA 2600 and NSA 3600 platforms with a SonicOS Expanded License or a High Availability License.
    • Supported on the TZ500 and higher TZ platforms with a SonicOS Expanded License or a High Availability (Stateful) Upgrade License.

    For licensing information, see SonicOS 8 Settings document.