Alto MS Series User Manual Page 92

  • Download
  • Add to my manuals
  • Print
  • Page
    / 108
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 91
88 Getting Started Guide
HA Overview Set Up High Availability
HA Overview
On Palo Alto Networks firewalls, you can set up two devices as an HA pair. HA allows you to minimize
downtime by making sure that an alternate device is available in the event that the primary device fails. The
devices use dedicated or in-band HA ports on the firewall to synchronize data—network, object, and policy
configurations—and to maintain state information. Device specific configuration such as management port IP
address or administrator profiles, HA specific configuration, log data, and the Application Command Center
(ACC) information is not shared between devices. For a consolidated application and log view across the HA
pair, you must use Panorama, the Palo Alto Networks centralized management system.
When a failure occurs on the active device and the passive device takes over the task of securing traffic, the event
is called a failover. The conditions that trigger a failover are:
One or more of the monitored interfaces fail. (Link Monitoring)
One or more of the destinations specified on the device cannot be reached. (Path Monitoring)
The device does not respond to heartbeat polls. (Heartbeat Polling)
HA Modes
You can set up the firewalls for HA in two modes:
Active/Passive— One device actively manages traffic while the other is synchronized and ready to
transition to the active state, should a failure occur. In this configuration, both devices share the same
configuration settings, and one actively manages traffic until a path, link, system, or network failure occurs.
When the active device fails, the passive device takes over seamlessly and enforces the same policies to
maintain network security. Active/passive HA is supported in the virtual wire, Layer 2 and Layer 3
deployments. For information on setting up your devices in an active/passive configuration, see Configure
an Active/Passive Pair.
Active/Active— Both the devices in the pair are active and processing traffic, and work synchronously to
handle session setup and session ownership. The active/active deployment is supported in virtual wire and Layer
3 deployments, and is only recommended for networks with asymmetric routing. For information on setting up
the devices in an active/active configuration, refer to the Active/Active High Availability Tech Note.
HA Links and Backup Links
The devices in an HA pair use HA links to synchronize data and maintain state information. Some models of
the firewall have dedicated HA ports—Control link (HA1) and Data link (HA2)—while others require you to
use the in-band ports as HA links.
The PA-200 and the VM-Series firewalls support a lite version of active/passive HA. HA lite provides configuration
synchronization and some runtime data synchronization such as IPSec security associations. It does not support
any session synchronization, and therefore, HA Lite does not offer stateful failover.
Page view 91
1 2 ... 87 88 89 90 91 92 93 94 95 96 97 ... 107 108

Comments to this Manuals

No comments