High Availability - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

Network Setup menu options

High Availability

Figure 74 No preferred gateway warning
Designating a connection as a preferred gateway:
From the Network Setup menu, click Network Setup. The Connections page appears.
1
Click on the edit icon next to the connection you want to make a preferred gateway.
2
Select the Preferred Gateway checkbox.
3
Click Update. The connection has now been enabled for load balancing.
4
High Availability
High Availability (HA) allows a second UTM Firewall appliance to provide network connectivity should the
primary UTM Firewall appliance fail. The UTM Firewall appliances do not have to be the same models to be
used in the HA pair. If you have two UTM Firewall appliances on the same network segment, you can
configure a shared IP address that is assigned to one or the other appliance (as an Ethernet alias address)
depending upon which appliance is available. This provides for simple high availability support, which is
useful when hosts on the LAN segment have their default gateway assigned as the shared IP address. This
allows these hosts to automatically switch from one UTM Firewall appliance to the other if an appliance
becomes unavailable. The two appliances negotiate for ownership of the shared IP address at any given
time. The appliance that currently has the address is termed the primary appliance while the other device is
termed the secondary appliance.
A shared IP address, such as 192.168.1.254, is automatically configured as an alias on the interface on that
network segment on one of the UTM Firewall appliances. This is done via simple negotiation between the
two UTM Firewall appliances such that one appliance has the IP address (the primary appliance) and one
does not (the secondary appliance). This shared IP address is in addition to the primary IP addresses of the
two UTM Firewall appliances (for example, 192.168.1.1 and 192.168.1.2) for the interface on the network
segment. The shared IP address and primary IP addresses of the two UTM Firewall appliances are usually
part of the same network (for example, 192.168.1.0/24), but need not be. Typically, hosts on the local
network use the shared IP address as their gateway, and only use the devices' primary IP addresses when
they need to contact a particular UTM Firewall appliance, such as to access the Management Console of that
appliance.
74
McAfee UTM Firewall 4.0.4 Administration Guide

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents