Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG310 19 HA Active Active & RED tunnel failover

Hey folks,

I have 2 XG 310 in an active-active HA. When failover occurs (Primary goes down), the RED tunnel goes down and there is no failover for the RED tunnel. I need to disable and re-enable the RED tunnel...

Is it the correct behavior in an HA deployment?

Thanks in advance.

Dardan.



This thread was automatically locked due to age.
Parents
  • Hello ,

    Thank you for reaching out to the community, 

    • An active-active HA cluster does not load-balance VPN sessions, UDP, ICMP, multicast and broadcast sessions, scanned FTP traffic, and traffic coming through wireless RED devices and access points. TCP traffic for the user portal, web admin console or telnet console, and H.323 traffic sessions are also not load-balanced between the cluster devices. Control traffic for all modules isn't load-balanced.

    • An active-active HA cluster will load-balance normal forwarded TCP traffic, including NAT (both SNAT & virtual host) forwarded TCP traffic. This includes TCP traffic passing through a proxy subsystem such as transparent proxy, direct proxy, parent proxy, and VLAN traffic.
    • HTTPS connection load-balancing is supported.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hello Vivek,

    Thanks for your reply.

    Perhaps, I was not very clear but I was not talking about traffic load-balancing.

    I wanted to know why VPN RED tunnel was not re-activated on the Auxiliary after failover (Primary goes down scenario) in my deployment.

    Thanks ans regards,

    Dardan.

  • Thank you for the update, during that time did you check the syslog.log and red.log ?

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • On the client side, there is no errors:

    Wed Jul 13 20:42:30 2022Z REDD INFO: server: Configuration uploader process starting

    Wed Jul 13 20:42:30 2022Z REDD INFO: server: (Re-)loading device configurations

    Wed Jul 13 20:42:40 2022Z REDD INFO: client: (Re-)loading device configurations

    Reading REDv2 key from STDIN:

    Reading REDv2 key from STDIN:

    < I disabled then re-enabled the RED interface >

    Wed Jul 13 20:47:31 2022Z REDD INFO: Red devices: Connected: 1 Disconnected 0 Enabled: 1 Disabled: 0

    Wed Jul 13 20:52:32 2022Z REDD INFO: Red devices: Connected: 1 Disconnected 0 Enabled: 1 Disabled: 0

    Wed Jul 13 20:57:33 2022Z REDD INFO: Red devices: Connected: 1 Disconnected 0 Enabled: 1 Disabled: 0

    On the server side, no errors...

    All our FWs run the latest firmwares. However, we do not use RED unified firmware.

    Thanks for your help.

Reply
  • On the client side, there is no errors:

    Wed Jul 13 20:42:30 2022Z REDD INFO: server: Configuration uploader process starting

    Wed Jul 13 20:42:30 2022Z REDD INFO: server: (Re-)loading device configurations

    Wed Jul 13 20:42:40 2022Z REDD INFO: client: (Re-)loading device configurations

    Reading REDv2 key from STDIN:

    Reading REDv2 key from STDIN:

    < I disabled then re-enabled the RED interface >

    Wed Jul 13 20:47:31 2022Z REDD INFO: Red devices: Connected: 1 Disconnected 0 Enabled: 1 Disabled: 0

    Wed Jul 13 20:52:32 2022Z REDD INFO: Red devices: Connected: 1 Disconnected 0 Enabled: 1 Disabled: 0

    Wed Jul 13 20:57:33 2022Z REDD INFO: Red devices: Connected: 1 Disconnected 0 Enabled: 1 Disabled: 0

    On the server side, no errors...

    All our FWs run the latest firmwares. However, we do not use RED unified firmware.

    Thanks for your help.

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?