- Both devices must be from the same product family and running the same TOS version.
- Each device must have a secure connection to the network, and the other device must be in the Transparent HA pair.
- Both devices must have SSLv3 capability (HTTPS server enabled, which is the default setting) and be able to communicate on TCP port 9591.
- A device configured with Transparent HA can only connect and communicate with a partner configured to talk to other IPS devices configured with TRHA. In other words, both machines participating must point to each other. Each device must be configured with the partner's serial number and IP address.
- After the communication channel is active, the IPS will synchronize the following tables:
- Blocked Streams
- Trusted Streams
- Rate Limited Streams
- Quarantined IP Addresses
NOTES:
- If your system has two devices communicating through Transparent HA, changing the global timeout for the connection table on one device will not propagate to the other device. You must make this change on each device accordingly.
- The SSLv3 tunnel relies on the device's HTTPS daemon. If you enable HTTP instead of HTTPS, communication will fail.
- With TRHA active, both devices will still be stand-alone devices; they do not synchronize configurations. The benefit of Transparent HA is that each device can understand what actions have occurred on their partner so that in the event of network convergence to the alternate path, blocks and rate limits will already be in place.