Firewall management and deployment
You can configure HA in firewalls deployed in gateway, bridge, and discover modes.
Sophos Central management
For non-HA firewalls managed from Sophos Central, we recommend that you do as follows:
- Deregister them from Sophos Central.
- Configure HA.
- Register them again for Sophos Central management.
You can then move the HA pair to a different group in Sophos Central. See Manage an HA pair in Sophos Central.
Firewall deployment modes
For firewalls deployed in discover mode, you must meet some requirements.
Gateway and bridge modes
You can configure HA in firewalls deployed in gateway and bridge modes.
See the following topics:
Discover mode
You can configure active-passive HA in TAP or discover mode.
- If one or both HA devices are in discover mode, you can't configure active-active HA.
-
You can't configure active-passive HA when the TAP interface is active. Do as follows:
- Go to the CLI of each firewall and deactivate the TAP interface.
- Establish HA and start the TAP interface again individually on both devices.
-
The TAP interface is active on the passive HA device.