SonicOS 8 High Availability

High Availability Config

The High Availability Config section on the Device > High Availability > Settings page provides the following information:

  • HA Mode - Indicates one of:
    • None - High Availability is not enabled on the unit.
    • Active/Standby - Active/Standby mode provides basic high availability with the configuration of two identical firewalls as a High Availability Pair. By default, Active/Standby mode is stateless, meaning that network connections and VPN tunnels must be re-established after a failover. To avoid this, Stateful Synchronization can be licensed and enabled with Active/Standby mode.
    • Active/Active DPI - Active/Active Deep Packet Inspection (DPI) mode can be used along with the Active/Standby mode. When Active/Active DPI mode is enabled, the processor intensive DPI services, such as Intrusion Prevention (IPS), Gateway Anti-Virus (GAV), and Anti-Spyware are processed on the standby unit, while other services, such as firewall, NAT, and other types of traffic are concurrently processed on the Active unit.
    • Active/Active Clustering - In this mode, multiple firewalls are grouped together as cluster nodes, with multiple Active units processing traffic (as multiple gateways), doing DPI and sharing the network load. Each cluster node consists of two units acting as a Stateful HA pair. Active/Active Clustering provides Stateful Failover support in addition to load-sharing. Optionally, each cluster node can also consist of a single unit, in which case Stateful Failover and Active/Active DPI are not available.
    • Active/Active DPI Clustering - This mode allows for the configuration of up to four HA cluster nodes for failover and load sharing, where the nodes load balance the application of DPI security services to network traffic.
  • HA Control Link - Indicates the port, speed, and duplex settings of the HA control link, such as X6 1 Gbps Full Duplex. When High Availability is not enabled, the field displays not configured. The HA control link is used to communicate heartbeats and other control traffic between the units. If the HA control link fails, X0 is used to communicate heartbeats between units; therefore heartbeats on both units should be in the same broadcast domain.
  • HA Data Link - Indicates the port, speed, and duplex settings of the HA data link, such as X7 1 Gbps Full Duplex. When High Availability is not enabled, the field displays not configured. The HA data link is used to transfer stateful data to keep session data synchronized between the units. The HA Data Link is not required when running in non-stateful HA.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden