On the Device Configuration (HA (High Availability)) screen, you can configure the following:
Note: These options are dynamic in that they will only display when the capability is available for the device.
Capability | Description |
Intrinsic HA: | Intrinsic HA monitors the device to detect hardware operating system failures and to automatically switch to the Layer-2 Fallback mode when a server outage or system failure is detected. You can use the Normal mode to configure the device to inspect traffic according to the Threat Suppression Engine (TSE) settings. You can use the Layer-2 Fallback mode to permit or block all traffic according to the fallback settings for each device segment. |
Transparent HA: | Transparent HA is for devices deployed in a redundant configuration in which one device takes over for the other in the event of system failure. When Transparent HA is enabled, the devices constantly update each other with their managed streams information (blocked streams, trusted streams, and quarantined hosts). When a system failure occurs, the failover device does not have to rebuild all of the current managed streams information. (Not supported by vTPS) |
Zero Power HA: | With Zero Power HA, you can ensure constant, non-interrupted flow of traffic. During a system outage, Zero Power HA bypasses the device and provides continuous network traffic. Bypass is available for the IPS as an external modular device or as optional bypass I/O modules on NX-Platform devices. (Not supported by vTPS) |
How To: Configure Network HA
- Log in to the SMS from a client.
- On the SMS toolbar, navigate to the Devices->All Devices and expand the tab.
- Select a device from the display window and do one of the following:
- Right-click and select Edit->Device Configuration.
- On the top menu select Edit->Details->Device Configuration.
- Double-click the device and click on Device Configuration tab.
- On the Device Configuration Wizard screen, click the HA (High Availability) tab.
- For Intrinsic HA: select one of the following and then click Apply::
- Normal - Overrides all INHA settings
- Layer-2 Fallback - Enables INHA configurations per segment
- For Transparent HA;
- Click the Enable check box.
- Enter the Partner IP Address.
- For Zero Power HA: select one of the following and then click Apply:
- Normal (default)
- Bypass IPS - for pass-through traffic.
- CCliClick OK to update the device.
Reference: SMS User Guide