Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to configure Active -Passive HA

I have done plenty of digging but I do not see any step by step guide to this other than whats provided by Sophos. I am not that familiar with Sophos products but I have been asked to configure Active Passive HA.

About my primary firewall interfaces: I have port 1 which is my WAN connected to my ISP, Port 2 which is connected to a small switch that is also connected to our phone system ( I am new so this environment is new to me), then in my case port 6 is our Lan which runs to our managed switch. 

Can anyone give me a quick run through on how this is supposed to be set up? Specifically the DMZ portion. Why does the DMZ look like a physical switch? Or is that stating set up a DMZ on both FW's then connect them both to that switch that is currently connected to port 2? I have looked through to documentation but in my case I do not have DMZ set up yet. Other than the DMZ zone and the link set up. I understand the functionality and how this appears to need to be set up. Just looking to connect the dots. I think with a little explanation I can get this all set up with ease.

Thanks!

 



This thread was automatically locked due to age.
Parents
  • Whatever port you are using to connect the two firewalls, put that port int he DMZ zone. You go into Network->Interfaces (and for the interface that is connecting both the firewalls) select DMZ as the network zone. Also note that you will be running a different subnet on this zone so use one that is not being used elsewhere (like you can use 192.168.255.0/30 subnet by giving one port a 192.168.255.1 address and the other 192.168.255.2 address)

Reply
  • Whatever port you are using to connect the two firewalls, put that port int he DMZ zone. You go into Network->Interfaces (and for the interface that is connecting both the firewalls) select DMZ as the network zone. Also note that you will be running a different subnet on this zone so use one that is not being used elsewhere (like you can use 192.168.255.0/30 subnet by giving one port a 192.168.255.1 address and the other 192.168.255.2 address)

Children
No Data