Hello!
We are trying to build an HA Cluster over two datacenters, each with two switches and one Sophos XG 330 (FW v17.5.7 MR-7). The LAN and WAN ports on the firewall are both LAG ports, connected to each switch. We would like to also use a LAG port for the dedicated HA port for an Active-Passive cluster, however, it seems we can't choose a LAG interface for the HA port even though it is in the DMZ zone with SSH access (the list of available ports is just empty).
Right now we just use one normal port for the HA, however after some failover tests, we noticed that if the switch with the HA link goes down, we have a split brain situation with the firewalls, since both firewalls at both datacenters still have a working LAN and WAN port.
So we were wondering if there is a way to use an LAG port for the dedicated HA port? I found some older threads discussing this over the old UTM firewalls and it seems like it was possible back then, so we are kinda confused why it doesn't work with the new XG anymore.
BR Daniel
This thread was automatically locked due to age.