...
Info |
---|
TCP connections are tracked via Connection Tracking and are synchronized to the Slave Firewall. However UTM functions such as IDS/IPS cannot be synchronized. Thus after a roll change all existing connections, which are scanned by a UTM function, are interrupted. |
Hinweis |
---|
The IP address range used for the "Cluster Interconnect" must not be used elsewhere (e.g. for the local network). Otherwise this will lead to routing problems! |
Requirements:
- LANCOM R&S®Unified Firewall with LCOS FX as of version 10.3
- Two Unified Firewalls of the same model as of UF-200 (except UF-50 and UF-100)
- The same firmware version has to be installed on both Unified Firewalls
- One Unified Firewall license on the Master firewall
- The configuration on the Master Firewall has to be complete
- At least one free Ethernet port on both devices
- The Gratuitous ARP of the Slave Firewall has to be transmitted by the switch in the local network
- Web browser for configuring the Unified Firewall.
The following browsers are supported:- Google Chrome
- Chromium
- Mozilla Firefox
Info |
---|
An HA cluster can only be used in a scenario with a series connection or stand-alone operation. |
Scenario:
- The configuration and the cabling for the Ethernet ports has to be the same on both Unified Firewalls
- eth0 is used for the internet connection to an upstream router and is connected to an intermediary switch
- eth1 is used for the local network and is connected to a switch
- eth3 is used for the connection between the two Unified Firewalls for the cluster synchronization (Cluster Interconnect)
Procedure:
1) Configuratuion Configuration of the Master Firewall:
1.1) Open the configuration of the Unified Firewall in a browser and go to the menu Network → Connections → Network Connections.
...
1.2) Go to the menu Firewall → High Availability.
1.3) Activate the function High Availability via the slider and change the following parameters:
- Initial Role: Select the option Master.
- HA Interface: In the dropdown-menu select a free Ethernet port to be used for the synchronization between the two Unified Firewalls (in this example the port eth3).
- Local IP: Assign an IP address in CIDR format (Classless Inter Domain Routing) for the Master Firewall. This IP address respectively / this network must not be used elsewhere in the configuration.!
- Remote IP: Assign an IP address from the same network as the Local IP to the Slave Firewall. IP addresses in another network cannot be used.
...
Hinweis |
---|
For the function High Availability the use of the same Ethernet ports is mandatory, as the configuration is identical. |
2.2) Activate the function High Availability via the slider and change the following parameters:
...
Hinweis |
---|
After synchronizing the configuration the Slave Firewall cannot be reached via its web interface! |
3. Reading out the HA cluster status:
The current status of the HA cluster can be read out on the Master firewall in the Overview on the right side under High Availability.
4) Operating the HA cluster in the LMC (optional):
Info |
---|
The LMC supports the HA cluster, however it cannot be configured via Smart-Config in the LMC. Therefore the HA cluster has to be configured manually. |
Hinweis |
---|
Before conducting a role change on an HA cluster and pairing the cluster with the LMC, a valid license has to activated on the Master firewall (the demo license is not sufficient). |
4.1) Set up the HA cluster as described in steps 1) and 2).
4.2) Connect the Master Firewall to the LMC as described in the following Knowledge Base article in step 2.2.2):
Pairing a LANCOM device with the LMC
4.3) In the LMC menu Devices, the HA cluster is marked by a corresponding symbol (under Model).