Used for the HA2 link to synchronize sessions,
forwarding tables, IPSec security associations and ARP tables between firewalls
in an HA pair. Data flow on the HA2 link is always unidirectional
(except for the HA2 keep-alive); it flows from the active firewall
(Active/Passive) or active-primary (Active/Active) to the passive
firewall (Active/Passive) or active-secondary (Active/Active). The
HA2 link is a Layer 2 link, and it uses ether type 0x7261 by default. The
HA data link can also be configured to use either IP (protocol number
99) or UDP (port 29281) as the transport, and thereby allow the
HA data link to span subnets. |