12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Selecting a Primary High Availability Fireboxdevices, use the two highest numbered ports on each Firebox. We recommend that you connectthe ports after you configure them.• HA does not operate correctly if one of the Fireboxes in the HA pair is a VPN endpoint in a VPNtunnel created and managed by the Management Server.• You cannot put a <strong>WatchGuard</strong> Management Server behind a gateway Firebox that is part of anHA cluster.NoteHigh availability requires an interface or interfaces dedicated specifically for HA synchronization.Selecting a Primary High Availability FireboxWhen you activate High Availability, each Firebox® in the pair must have a Fireware® feature keyenabling the same version of Fireware appliance software. We recommend that you select the Fireboxwith the most features as the primary Firebox. If you purchase an upgrade for your High Availability pair,you must apply the upgrade to the serial number of the primary Firebox when you activate the upgradeon the LiveSecurity web site. Both Fireboxes in the High Availability pair will use the license features ofthe primary Firebox.If you use IPSec VPN tunnels that use a VPN certificate for authentication, the secondary Firebox mustget its own IPSec VPN certificate. Only the Management Server certificate is copied from the primaryFirebox to the secondary Firebox when a failover occurs.Configuring HA for Firebox X e-Series Devices1 From Policy Manager on the primary HA Firebox, select Network > High Availability.The High Availability dialog box appears.344 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!