Below is an HA related configuration example:
Primary | Secondary | |
---|---|---|
VRRP Group: LAN1 Virtual IP: 172.16.1.1/25 | LAN1: 172.16.1.2/25 | LAN1: 172.16.1.2/25 |
LAN1 DHCP: on Gateway: 172.16.1.1 Range: 172.16.1.100-199 | LAN1 DHCP: on Gateway: 172.16.1.1 Range: 172.16.1.100-199 | |
Heartbeat interface | LAN2: 192.168.102.1/25 | LAN2: 192.168.102.2/25 |
Please follow these steps to access the network using HA:
- Configure client with DHCP to access network.
- Configure VRRP interface DHCP service on Cloud Edge Cloud Console or on-premise console.
- The DHCP Server Gateway should be filled with virtual IP address.
- When LAN1 is used as DHCP Server, you need to configure DHCP service on Primary and Secondary box respectively on-premise console. The LAN1 DHCP configurations should be the same as well.
- Configure client network settings to obtain IP address through DHCP.
- Configure VRRP interface DHCP service on Cloud Edge Cloud Console or on-premise console.
- Configure client with Static IP address setting to access network.
- Configure client IP/mask in the same subnet with the VRRP interface.
- Configure client gateway with virtual IP address.
You can create an HA group from Cloud Edge Cloud Console. An HA group consists of two Cloud Edge gateways. The gateways can be registered or unregistered. A gateway can belong to only one HA Group.
Before creating an HA, ensure the following:
- Gateways are deployed in routing mode.
- Both gateways are the same hardware model. Currently, only CE50G2 supports HA function.
- Both gateways have be same software version.
- Timezone should be same.
- System time error should be less than 5 minutes.
Please note that in the factory default configuration, all boxes have the same interface configurations. You need to change the interface settings before HA group construction.
Follow these steps to create HA:
- Configure the VRRP interfaces on both boxes. They should be in the same subnet.
- Configure the heartbeat interface of both boxes. They should be in the same subnet. Please note that only LAN2 and LAN3 are used for heartbeat interface.
- Connect an ethernet cable directly between the heartbeat interfaces for each gateway that will be a member of the HA group.You must use the same interface on each gateway (LAN2-to-LAN2 or LAN3-to-LAN3).
- Navigate to Gateway > High Availability Management.
- Click Create HA Group. The Create HA Group wizard opens.
- In the Create HA Group and Choose Operation Mode page, specify the following details:
Options Description HA group name Type a name to identify this HA group Operation mode Current only supports Active-Passive mode Authentication method Select one of the following: None/Simple Enable Select one of the following: On/Off - Click Next.
- In the Configure Primary Device page, configure settings for the Cloud Edge gateway that will be the primary gateway in the HA group.
Options Description Primary HA device Select the gateway from the drop-down list that you want to designate as the HA primary gateway. Only devices that support an HA group configuration are listed. Role A read-only field set to Primary, which is the role assigned to this gateway Priority Enter a priority number for this gateway (1-253). Default is 253. The gateway with the higher the priority is active. Heartbeat interface Select the L3 interface from the drop-down that Cloud Edge uses for communicating with the peer HA gateway. For Cloud Edge 50G2 gateway, only eth2 or eth3 can be selected as the heartbeat interface. Heartbeat interface IP/Netmask If not already configured, you must enter an IPv4 address and netmask for the heartbeat interface. - Click Next.
- In the Configure Secondary Device page, configure settings for the Cloud Edge gateway that will be the secondary gateway in the HA group.
Options Description Secondary HA device Select the gateway from the drop-down list that you want to designate as the HA primary gateway.
Only devices that support an HA group configuration are listed.Role A read-only field set to Secondary, which is the role assigned to this gateway Priority Enter a priority number for this gateway (1-253). Default is 100. Heartbeat interface The L3 interface is pre-selected from the drop-down and is the same interface selected for the primary HA device.
Cloud Edge uses this interface for communicating with the peer HA gateway.Heartbeat interface IP/Netmask If not already configured, you must enter an IPv4 address and netmask for the heartbeat interface.
It must be on the same subnet as the heartbeat IP address configured for the primary. - Click Next.
- In the Configure Takeover When Failure Occurs page, configure settings for the Cloud Edge HA group when a failure happens and takeover occurs.
Options Description Preemption Select one of the following: - On (default): Primary gateway will return to active role after it recovers from a previous failure.
- Off: Primary gateway does not automatically resume the active role after recovery from a failure.
User must perform manual fail-over.
Monitor interface Select one or more interfaces to monitor. Cloud Edge monitors only physical interfaces.
It is recommended to monitor all physical interfaces with traffic.Monitor IP/FQDN At most two IP addresses or FQDNs can be used as monitor hosts. Takeover triggers You must enter values for the following: - Heartbeat failure times: Indicates the number of heartbeat failures before the passive gateway takes over from the failed gateway (default is 3, range is 3-6)
- Ping failure times: Indicates the number of ping failures before the passive gateway takes over from the failed gateway (default is 3, range is 3-6)
- In the Configure Virtual Router Redundancy Protocol (VRRP) Group page, add one or more VRRP groups.
- Click Next. The summary page opens.
- Review the summary of the HA group settings.
- Click Save.
Actions | Description |
---|---|
Update HA configurations. Note that HA group name, Primary HA device, Secondary HA device, Heartbeat interface, and Heartbeat interface IP/Netmask are not allowed to be edited. | |
Force trigger HA role switch. After performing this action, active switches to standby and standby switches to active. | |
Enable HA group. HA will start to work if you perform this action. | |
Disable HA group. HA will not work if you perform this action. | |
Tear down HA group and remove it from Cloud Edge Cloud Console. |
Follow these steps to manually update HA group firmware version:
- Navigate to Gateways > Gateway Management > (gateway name of any box in HA group) > Updates.
- Check the available firmware packages, and click Update.
After performing the update, the HA group will start firmware update process. The Standby will first update the firmware version then the Active will do update automatically.
In order to rollback the firmware version for HA group, you need to go to Cloud Edge on-premise console on both boxes, and manually rollback the firmware version of each box.
When replacing a gateway in HA group, please ensure the following:
- The new Cloud Edge gateway should have same hardware model and software version with gateways in HA group.
- The new Cloud Edge gateway should have same network configuration with the old gateway.
Follow these steps to perform the replacement:
- Move the Heartbeat interface ethernet cable from the old gateway to the new gateway.
- Go to CECC web console and navigate to Gateways. Select Replace.
- Specify the new Cloud Edge gateway serial number.
- Click Replace.
- Remove the old Cloud Edge gateway from the network.
- Add the new Cloud Edge gateway to the network.