Configure active-active HA using QuickHA

How to use QuickHA to configure an active-active HA cluster.

To configure active-active QuickHA, do as follows:

Caution You must make sure that both appliances have different IP addresses initializing the QuickHA mode. For example, you can't have both devices using the default 172.16.16.16 address.
  1. Connect the Sophos Firewall devices using a network cable plugged into the dedicated HA port on both units.
  2. Sign in to the web admin console of the primary Sophos Firewall device and go to System services > High availability.
  3. For Initial device role, select Primary (Active-Active).
  4. Ensure QuickHA is selected. You’ll see default settings (which you can change), as described in the steps that follow.
  5. QuickHA generates a passphrase automatically. You can also change the passphrase manually.
    Note The passphrase is used only once to generate the SSH keys used to encrypt communication over the HA link. It's then deleted.
  6. QuickHA selects a dedicated HA link automatically. You can also select an interface manually.

    By default, QuickHA selects the first unbound interface. If this isn't available, it uses the first DMZ port. This interface is renamed QuickHA mode interface and is assigned an IPv4 address from the link local range, 169.254.0.0/16.

    Warning If QuickHA selects a DMZ port that’s already in use, its current configuration is overwritten.
  7. Click Initiate HA.
  8. Sign in to the web admin console of the auxiliary Sophos Firewall from PortA, and go to Network > Interfaces. Make sure the IP address of PortA is in same subnet as PortA of primary Sophos Firewall.
    Note In this example, we will configure PortA as the peer administration port. So, PortA of the auxiliary node must be in same subnet as PortA of the primary node. If it isn't, QuickHA won't work, and the following error appears in /log/syslog.log on the primary node.

    Validation Failed For Ha interface IP.

    For example, if PortA of the primary node is 192.168.3.254/24, then PortA of the auxiliary node can be 192.168.3.253/24. However, it cannot be 172.16.16.16/24

  9. Go to, System services > High availability.
  10. Select Auxiliary as the device role.
    Tip QuickHA assigns the peer administration port based on the interface you are currently using to access the web admin console of the auxiliary Sophos Firewall web admin console. For example, if you're connected to PortA, this interface becomes the peer administration port on both Sophos Firewall devices.
  11. Select QuickHA and enter the same passphrase used on the primary Sophos Firewall device.
  12. Click Initiate HA. You see a message about the configuration being overwritten. This is because the configuration will be synchronized from the primary Sophos Firewall device.