Configuring High Availability
Sample Implementation on Two Gateways
The following procedure illustrates how to configure HA for the following tw
NetDefend gateways, Gateway A and Gateway B:
T
able 15: Gateway Details
In
ternal Networks
Intern
et Connections
LAN Network IP Address
LAN Network
Subnet Mask
DMZ Network IP Address
DMZ Network
Subnet Mask
The gateways have two internal networks in common, LAN and DMZ. This means
that you can configure HA for the LAN network, the DMZ network, or both. You
can use either of the networks as the synchronization interface.
The procedure below shows how to configure HA for both the LAN and DMZ
networks. The synchronization interface is the DMZ network, the LAN virtual IP
address is 192.168.100.3, and the DMZ virtual IP address is 192.168.101.3.
Gateway A is the Active Gateway.
To
configure HA for Gateway A and Gateway B
1. Connect the LAN port of Gateways A and B to hub 1.
126
Gateway A
LAN, DMZ
Primar
y and secondary
192.169.100.1
255.255.255.0
192.169.101.1
255.255.255.0
Gateway B
LAN,
DMZ
Primary only
192.169.100.2
255.255.255.0
192.169.101.2
255.255.255.0
D-Link NetDefend firewall User Guide
o