Configure the primary XG Firewall

You must configure the auxiliary device before you can configure the primary device and enable HA.

  1. Go to System services > High availability.
  2. Specify the initial HA device state.
    OptionDescription
    Initial HA device state Primary
  3. Specify the HA configuration mode for the cluster.
    OptionDescription
    Active–Active The primary device receives all network traffic and load-balances the traffic using the auxiliary. Both the primary and auxiliary devices process traffic. The auxiliary takes over if a power, hardware, or software failure occurs on the primary.
    Active–Passive The primary device processes all network traffic and the auxiliary remains in stand-by mode. The auxiliary becomes active and takes over only in case of a power, hardware, or software failure on the primary.
  4. Type and confirm a passphrase.
    Note The devices in the cluster must have the same passphrase.
  5. Select a dedicated HA link.
    OptionDescription
    Dedicated HA link The link to be monitored. Peers in an HA cluster continuously monitor the dedicated HA link and the interfaces configured to be monitored.
    Note The peer device must use the same HA link. Specify this port as the HA link port on the peer. For example, if you choose port E on the primary device, you must also choose port E on the auxiliary device.
    Note The IP address of the HA link for the peer device must be on the same subnet.
  6. Specify the settings.
    OptionDescription
    Peer HA link IPv4 IP address configured on the HA link port of the auxiliary device.
    Peer administration port Port that is used for administration purposes on the auxiliary device.
    Peer administration IP IP address that provides access to the administration console of the auxiliary device.
  7. Select ports to be monitored for HA status.
    If any monitored port goes down, the device will leave the cluster and failover will occur.
    Note This feature is not supported in virtual security devices.
  8. Click Enable HA.
    The primary device pushes its configuration to the auxiliary.

When HA is active, the devices will synchronize automatically. To force the device to push configuration updates to the auxiliary, click Sync auxiliary.

If you have configured the device for Active–Passive mode, you can force the auxiliary to take over as the primary device by clicking Put on standby.