Configuration:
Source: http://help.sonicwall.com/help/sw/por/6950/26/2/4/content/HA_AAClusteringConfig.html
Configuring Active/Active Clustering
Configuring Active/Active Clustering High Availability
Active/Active Clustering High Availability allows for the configuration of up to four HA cluster nodes for failover and load sharing. Each node can contain either a single appliance or an HA pair.
To configure Active/Active Clustering High Availability:
1
|
8
|
9
|
10
|
11
|
Go to the High Availability > Monitoring page and follow the steps in Configuring Active/Active Clustering High Availability Monitoring .
|
12
|
13
|
Configuring Active/Active Clustering High Availability Monitoring
The configuration tasks on the High Availability > Monitoring page are performed on the Primary unit and then are automatically synchronized to the Secondary. These settings only affect the HA pair in the Cluster Node that is selected at the top of the page.
To set the independent LAN management IP addresses and configure physical and/or logical interface monitoring, perform the following steps:
5
|
7
|
The Primary IP Address and Secondary IP Address fields must be configured with independent IP addresses on a LAN interface, such as X0, (or a WAN interface, such as X1, for probing on the WAN) to allow logical probing to function correctly.
12
|
For additional information on verifying the configuration, see Verifying Active/Active Clustering Configuration .
Configuring Active/Active DPI Clustering High Availability
Active/Active DPI Clustering High Availability allows for the configuration of up to four HA cluster nodes for failover and load sharing, where the nodes load balance the application of Deep Packet Inspection (DPI) security services to network traffic.
For the Cluster Links and the Control Links, each unit in Cluster Node 1 is connected to each unit in the peer node (Cluster Node 2). For best practice, use the same set of interfaces on each unit in each node. (For example, connect X8 in one unit to X8 in the peer unit, and do the same if you are using X9 or X10, etc. However, there is no restriction on which ports you use.
Figure 59. Active/Active DPI clustering high availability
To configure Active/Active DPI Clustering High Availability:
1
|
If you have physically connected the Active/Active DPI Interface as described in Physically Connecting Your Appliances , you are ready to configure Active/Active DPI in the SonicOS management interface.
3
|
6
|
9
|
10
|
11
|
12
|
14
|
15
|
Go to the High Availability > Monitoring page and follow the steps in Configuring Active/Active Clustering High Availability Monitoring .
|
16
|
17
|
Configuring VPN and NAT with Active/Active Clustering
Extra considerations must be taken when configuring the following features in an Active/Active Clustering environment:
Configuring VPN with Active/Active Clustering
VPN policy configuration requires association with a Virtual Group when running in Active/Active Clustering mode. In the VPN Policy window, both the Network and Advanced tabs have new configuration options for creating this association.
On the Network tab, Virtual Group address objects are available for the Choose local network from list option. These Virtual Group address objects are created by SonicOS when virtual IP addresses are added, and are deleted when the virtual IP is deleted.
If creating a VPN Policy for a remote network, Virtual Group address objects may also be available. For example, this graphic shows one with the custom name Active-Active-Lan-Host-1.
On the Advanced tab, you can select the Virtual Group number for the VPN Policy Group setting. The default is Virtual Group 1.
Configuring a NAT Policy with Active/Active Clustering
When running in Active/Active Clustering mode, NAT policy configuration includes Virtual Group settings. Default NAT policies are created by SonicOS when virtual IP addresses are added, and are deleted when the virtual IP is deleted. You can specify a Virtual Group or select Any when creating custom NAT policies. This graphic shows the NAT policy automatically created for Virtual Group 2 on interface X1.
This graphic shows the selections for the Virtual Group option in the Add NAT Policy window when creating a custom NAT policy.
Leave A Comment?
You must be logged in to post a comment.