Skip to content
Last update: 2021-10-15

QuickHA

QuickHA provides a way to easily set up Sophos Firewall as a high availability system with the minimum configuration steps by automatically selecting default configuration values.

QuickHA lets you set up Sophos Firewall as a high availability (HA) system easily and quickly.

You can use QuickHA to set up HA systems using both hardware and software appliances. It uses pre-designated HA ports to minimize your input.

You can configure your Sophos Firewall devices in any order.

Note

You can't enable HA if you turned on STP on a bridge interface.

To use QuickHA, do the following.

Caution

You must make sure that both appliances have different IP addresses initializing the QuickHA mode. For example, you can't have both devices using the default 172.16.16.16 address.

  1. Connect the Sophos Firewall devices using a network cable plugged into the dedicated HA port on both units.
  2. Sign in to the web admin console of the primary Sophos Firewall device and go to System services > High availability.
  3. Select the initial device role.
  4. Ensure QuickHA is selected. You’ll see default settings (which you can change), as described in the steps that follow.
  5. QuickHA generates a passphrase automatically. You can also change the passphrase manually.

    Note

    The passphrase is used only once to generate the SSH keys used to encrypt communication over the HA link. It's then deleted.

  6. QuickHA selects a dedicated HA link automatically. You can also select an interface manually.

    By default, QuickHA selects the first unbound interface. If this is not available, it uses the first DMZ port. This interface will be renamed QuickHA Mode interface and assigned an IPv4 address from the link local range, 169.254.0.0/16.

    Caution

    If QuickHA selects a DMZ port that’s already in use, its current configuration will be overwritten.

  7. Click Initiate HA.

  8. Sign in to the web admin console of the auxiliary Sophos Firewall from PortA, and go to Network > Interfaces. Make sure the IP address of PortA is in same subnet as PortA of primary Sophos Firewall.

    Note

    In this example, we will configure PortA as the peer administration port. So, PortA of the auxiliary node must be in same subnet as PortA of the primary node. If it isn't, QuickHA won't work, and the following error appears in /log/syslog.log on the primary node.

    Validation Failed For HA interface IP

    For example, if PortA of the primary node is 192.168.3.254/24, then PortA of the auxiliary node can be 192.168.3.253/24. However, it cannot be 172.16.16.16/24

  9. Go to, System services > High availability.

  10. Select Auxiliary as the device role.

    Tip

    QuickHA assigns the peer administration port based on the interface you are currently using to access the web admin console of the auxiliary Sophos Firewall web admin console. For example, if you're connected to PortA, this interface becomes the peer administration port on both Sophos Firewall devices.

  11. Select QuickHA and enter the same passphrase used on the primary Sophos Firewall device.

  12. Click Initiate HA. You see a message about the configuration being overwritten. This is because the configuration will be synchronized from the primary Sophos Firewall device.

The following status messages are displayed during the QuickHA setup process:

Message Description
Device Discovery Started. Dedicated HA link configured. QuickHA confirms that a dedicated link has been configured.
One time Password set for dedicated Interface. Device Discovery In-Progress. QuickHA is trying to connect the primary and auxiliary devices.
Peer detected. Initial SSH Handshake In-Progress. The auxiliary device has been detected and the initial connection is being established.
Peer detected. Initial Synchronization Started. Configuration sync is in progress.
Established HA has been established.
Not established HA has not been established. Please check all settings and connections.
Back to top