HA roles and statuses
To see the HA roles and statuses for the devices, go to System services > High availability and see High availability status.
Sophos Firewall that's configured as the main Sophos Firewall for the network. If both firewalls are online, this is the Sophos Firewall through which traffic flows.
The designation is dynamic. When the auxiliary device takes over, the designation changes from primary to auxiliary.
|Sophos Firewall that's configured as the secondary Sophos Firewall for the network. If both firewalls are online, this is the Sophos Firewall that is the inactive hot spare in active-passive mode. In active-active mode, the auxiliary firewall also processes the traffic.
You can see the following statuses for the HA devices:
Both devices can be active in active-active mode. The primary device makes the decisions.
The active device is the primary device in active-passive mode.
|The device is passive in active-passive mode.
|The auxiliary device isn't available. It likely has a fault.
|The device has a fault. Reasons can include the monitoring port being down, a firmware update is in progress, the device is restarting, or another network issue. Note that a fault status doesn't mean hardware failure.
You can see the following status messages when using QuickHA:
|Device discovery started. Dedicated HA link configured.
|QuickHA confirms that a dedicated link has been configured.
|One time Password set for dedicated Interface. Device discovery in-progress.
|QuickHA is trying to connect the primary and auxiliary devices.
|Peer detected. Initial SSH handshake in-progress.
|The auxiliary device has been detected, and the initial connection is being established.
|Peer detected. Initial synchronization started.
|Synchronization of the configuration is in progress.
|HA has been established.
|HA hasn't been established. Check all settings and connections.