Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Options for moving XG firewall in HA mode between physical locations

Howdy!

My company is moving our XG firewalls from one data center to another. The move requires configuration changes of various sorts (e.g., WAN port IP address). The firewalls are currently running in HA Active-Passive mode. I'll call the active device at the old data center "Device A" and the standby device "Device B" to avoid future confusion. I'd like to move the secondary device (Device B) to the new data center, configure it appropriately and test it. Once I'm happy that it's configured correctly, I would then move the other device (Device A) from the old data center to the new one and install it there.

Without breaking HA prior to moving Device B, will Device A come up as the secondary at the new data center and receive the updated configs from Device B? To avoid issues with having two firewalls possibly active at the same time, I won't connect device B to the WAN or LAN until I'm sure of B's status.

Or, should I break HA prior to moving Device B, configure B appropriately at its new home, then re-establish HA with B as the active box and A as the secondary/passive? I figure this would be the safer route, but it'd be nice not to have to fiddle with HA unless I have to. Again, to avoid issues with having two firewalls possibly active at the same time, I won't connect B to the WAN or LAN until HA is re-established.

Thanks for your thoughts and ideas.

Sincerely,

Chris M.



This thread was automatically locked due to age.
Parents
  • Best bet is to move the units together, plug it up at the new data center.  Before you move over to the new data center, though, you should be able to test new IP address using your laptop or a generic router to verify traffic is up.  Then make the shift, update the WAN interface configuration after moving the equipment into the new datacenter.

    The issue with trying to move Device B to the new DC location whether in HA mode or removed, is lack of a license to apply since Device A will still be the active licensed appliance.  I think this might be feasible if you had Active/Active configured.  A lift and shift may be your best option here, just do some initial testing with the assigned IPv4 block you got from the new datacenter before the move.

Reply
  • Best bet is to move the units together, plug it up at the new data center.  Before you move over to the new data center, though, you should be able to test new IP address using your laptop or a generic router to verify traffic is up.  Then make the shift, update the WAN interface configuration after moving the equipment into the new datacenter.

    The issue with trying to move Device B to the new DC location whether in HA mode or removed, is lack of a license to apply since Device A will still be the active licensed appliance.  I think this might be feasible if you had Active/Active configured.  A lift and shift may be your best option here, just do some initial testing with the assigned IPv4 block you got from the new datacenter before the move.

Children
No Data