Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

High Availability - Dedicated Link Loss ( no split-brain )

Hi,

im just having a quick question. Our two XG450 are splitted between two datacenters. The dedicated HA Link is connected via Fibre. All other links are connected to the switches inside the datacenter. Sadly one of the SFP died last week, but the amazing thing was that the Firewall did not fell into a split brain mode. It kept working like nothing happened and you could clearly see that the active-passive cluster was still intact. Is there some feature i didn´t know about where the auxilary appliance can check if the primary device is still online via its peer administration ip ?

I hope you can understand what I mean. Unfortunately English is not my main language

Thank you in advance Slight smile



This thread was automatically locked due to age.
  • As all used interfaces have L2 connectivity, it is possible XG master see the "other side". (and the peer see the master)

    That would be clever ... but I haven't heard anything about it yet.

    But i think the sync isn't working. 

    How about HA-status ?


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • SFOS does have a mechanism to prevent this situation. Essentially before the AUX Appliance takes over, it will check, if the Primary still is activate and accept / send traffic. In that case, the Aux will not take over, preventing a Primary-Primary Situation. 

    __________________________________________________________________________________________________________________