D-Link NetDefendOS User Manual page 836

Network security firewall
Hide thumbs Also See for NetDefendOS:
Table of Contents

Advertisement

Chapter 11: High Availability
as the cluster. Ideally, there will also be a second, backup designated router to provide OSPF
metrics if the main designated router should fail.
PPPoE Tunnels and DHCP Clients
For reasons connected with the shared IP addresses of an HA cluster, PPPoE tunnels and DHCP
clients should not be configured in an HA cluster.
Disabling Heartbeats on Unused Interfaces
It is recommended to disable heartbeats on Ethernet interfaces that are not being used. If this is
not done there is a risk that this could cause repeated failovers or even both units going active
because the HA mechanism will see the unused interface as a failed interface. The higher the
proportion of unused interfaces there are in a cluster, the more pronounced the effect of sending
heartbeats on unused interfaces becomes.
Both Units Going Active
In the case of a misconfiguration of an HA cluster, a worst case scenario could arise where both
the master and slave think the other unit has failed and both can go active at the same time
resulting in the failure of correct traffic flow.
This is usually identified by examining the log messages generated by both units. An
active-active situation might be caused by unused interfaces not having heartbeats turned off
(as discussed previously) or possibly a connection problem such as the sync interfaces not being
able to communicate.
836

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents