12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Upgrading Software in an HA ConfigurationBacking up an HA configurationWhen a Firebox is in a High Availability pair, you can back up the flash image of the Firebox only when itis the active Firebox. This is because the backup image includes the system and policy information, certificates,and licenses that do not exist on the secondary Firebox until failover. To create a backup image(.fxi) of the active Firebox:1 From Policy Manager, select File > Backup.2 Type the configuration passphrase. Click OK.3 Type and confirm an encryption key. This key is used to encrypt the backup file.Type a strong encryption key that is easy to remember.4 Browse or type the location for the backup file. Click OK.The backup file is created.5 Click OK when the backup is complete.Upgrading Software in an HA ConfigurationIf you install the software on the active Firebox®, the standby Firebox in the HA configuration does notautomatically upgrade. You must upgrade each Firebox. Upgrade the active Firebox first. When itrestarts, the standby becomes the active Firebox. You can then upgrade that Firebox. You cannotupgrade the software on a Firebox that is in standby mode.Using HA with Signature-based Security ServicesGateway AntiVirus and Intrusion Prevention Service (IPS) signature databases do not automatically synchronizebetween active and standby HA devices.If the antivirus and IPS features are enabled and an event occurs that causes the standby Firebox® tobecome active, this device can have a version of the Gateway AntiVirus and IPS signature databases thatis not current (especially if it was in standby mode for a long time). Until an update of the databaseoccurs, there is some time when a new virus or IPS attack can bypass the Firebox.To minimize this problem, keep the automatic signature update intervals for Gateway AntiVirus andIntrusion Prevention Service enabled and short. If possible, force a manual signature update on the newactive Firebox immediately after the failover occurs.Using HA with Proxy SessionsWhen High Availability is activated with the default configuration, all outgoing TCP sessions are disconnectedwhen a failover event occurs. <strong>User</strong>s must manually reestablish all interactive or persistent sessions.This is because proxy session state is not retained between HA peers, and the defaultconfiguration has a default TCP-proxy for all sessions. Packet filter sessions are maintained, but thepacket filter is not used by default. Consider adding specific packet filter policies to your configurationfor telnet, ssh, or any other policy for which you want failover. Note that IPS does not operate with thesenew policies.348 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!