This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Clustering & Redundancy Limitations

Hi all,

Regarding the clustering/HA features of XG. The best practice advice seems to be that the clustering is only supported within a rack - e.g. two XGs, with a CAT6 cable directly connecting one HA port to another. Clustering two XG firewalls across two geographic sites is - correct me if i'm wrong - not supported. Even if connected by high-bandwidth, low latency links.

Therefore to achieve redundancy, you need to run two separate firewalls, two separate sets of firewall rules, public IP addresses, etc.

This seems like quite a limitation - is cross-site clustering on the road map for a future release? How do other XG users correctly achieve redundancy with two data centers?

Thanks



This thread was automatically locked due to age.
Parents Reply
  • This will, like UTM9 work fine. You can link both together and be happy. But be careful with those issues, which needs to be resolved like Master-Master. 

    Also (as far as i know) XG does not support Jumbo Frames on the HA Port. So most likely most of those Links requires Jumbo Frames. 

Children
  • I tried clustering across two sites with our XGs and it didn't work well at all, despite being the link being low latency. So I didn't get to the point of having a split brain scenario.

    Most other firewalls i've used can do cross-site clustering without issue, so i'm very surprised it's not supported. It means that you need to either have a 'warm spare' firewall without any conflicting config on it, or double up on public IP addresses and have run two separate XGs (not clustered). Both of these scenarios are far from ideal.

    It would be good to know that this is on definitely on the product roadmap.

     

    Thanks