Define the high availability (HA) failover conditions for active/passive HA
firewalls.
Where Can I Use
This? | What Do I Need? |
Define the link monitoring and path monitoring conditions for your active/passive HA
firewalls to define the failover conditions and establish what will cause a firewall
in an HA pair to fail over, an event where the task of securing traffic from the
previously active firewall to its HA peer. The
HA Overview
describes the conditions that cause a failover.
You can monitor multiple IP path groups per logical router or VLAN. You can enable
each path group with one or more IP addresses and give each its own peer failure
conditions. Additionally, you can set these failure conditions at both the
path-group level and the broader logical router or VLAN group level using
Any or All fail checks to
determine the status of the active firewall.
Before you enable path monitoring and define the HA failover conditions, you must
also:
-
Check reachability for destination IP groups in your logical routers.
-
Ensure that VLANs (for which you intend to enable path monitoring)
include configured interfaces.
-
Obtain the source IP address that you’ll use to receive pings from the
appropriate destination IP address.