This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HA setup with VLAN

Hi,

 

I have 2 XG210 boxes and I want to enable HA. Problem is that on 5 ports I am using VLAN's and only last port is without any VLAN. When I go through HA configuration on aux device I selected nontagged port as dedicated HA link but on primary device I have a problem because I cannot select tagged port as Peer Administration Port. So my question is - is there a way to setup HA on device which has VLAN's on 5 ports and only 1 port dedicated for HA has no VLAN.

 

Pawel



This thread was automatically locked due to age.
Parents
  • Hi Pawel, 

    You can check #7 in my guide here for HA prerequisites. The other articles on HA deployments are easily available online.

    Thanks

  • Sachin,

    Thanks for links but I think I read this and some other articles but they all refer to HA sync port which I fully understand must be a dedicated physical port.  My question is related to Peer Administration Port which from my understanding is just used to connect through webUI to aux device so I don't see reason why it would need another dedicated physical port. Based on what I currently see I need 2 dedicated ports to have HA - one for HA Link and one as Administration Port and this is what no manual mentions :)

    Pawel 

  • Pawel,

    you cannot use a port where VLAN exists for even the Administration port. It is a good feature! Open it on ideas.sophos.com

    Thanks

  • Good idea Luk. In mean time I did following to solve my configuration problem (I used fact that both Sophos XG and my switch support tagged and non-tagged traffic on same port)

    - In my case port 5 had 3 VLAN's and one of them was management VLAN which I wanted to use as administration port

    - I removed management VLAN from interface 5 and configured its IP directly in Port 5

    - On switch to which Sophos Port 5 is connected I configured that non-tagged traffic should go to management VLAN

    - In HA configuration I choose port 5 as Administration port

    I need to test switch-over but for now HA is enabled and up and running :)

    Pawel

Reply
  • Good idea Luk. In mean time I did following to solve my configuration problem (I used fact that both Sophos XG and my switch support tagged and non-tagged traffic on same port)

    - In my case port 5 had 3 VLAN's and one of them was management VLAN which I wanted to use as administration port

    - I removed management VLAN from interface 5 and configured its IP directly in Port 5

    - On switch to which Sophos Port 5 is connected I configured that non-tagged traffic should go to management VLAN

    - In HA configuration I choose port 5 as Administration port

    I need to test switch-over but for now HA is enabled and up and running :)

    Pawel

Children