Failover
6. Configure the failover parameters for the preferred primary Equalizer; in this case
sn01
on
the VLAN
172net
. Use the check boxes and sliders as necessary. You will not be able to
change the
Failover IP Address
. The
Failover IP Address
is used primarily as a server gateway and
to provide an IP address for system services such as the GUI, SSH, etc.
When configuring a Failover IP address on a subnet on Equalizer, make absolutely sure that
no other system on the network is using that Failover IP address other than the Equalizers
configured into failover.
If the IP address IS used by another system on the net, and a failover occurs, BOTH of the
failover peers will transition to and remain in BACKUP mode! The way to fix the problem is
to:
1. Remove the duplicate IP address from the offending system.
2. Reboot one of the peers.
The peers should transition to their proper failover modes.
This applies to both Active/Passive and Active/Active failover.
7. Check the appropriate check boxes in the
Use Subnet IP Address
pane as follows:
a. Checking the
Command Transfer
checkbox will designate this subnet as the subnet
over which the configuration file transfers (between preferred primary and pre-
ferred backup) can occur.
b. Checking the
Heartbeat
checkbox will allow the failover peers to probe one
another over the subnet. At least one subnet must have a
Heartbeat
flag enabled.
Note
-
Command Transfer
and
Heartbeat
use the subnet IP address, not the failover IP address.
8. Check the appropriate check boxes in the
Services on Failover IP Address
pane to select the
allowable services that will be available:
a.
HTTP
- when enabled the Equalizer will listen for
HTTP
connections on the Fail-
over IP address on the subnet.
b.
HTTPS
- when enabled the Equalizer will listen for
HTTPS
connections on the Fail-
over IP address on the subnet.
c.
SSH
- when enabled
SSH
login will be permitted on the Failover IP address on
the subnet.
d.
SNMP
- when enabled
SNMP
will accept connections on the Failover IP address
on the subnet.
e.
Envoy
-when enabled this will allow Envoy to monitor this subnet for failover
f.
Envoy Agent
- when enabled this will allow an Envoy agent to monitor this sub-
net for failover
10. Adjust the
Heartbeat Interval
time in seconds (default: 2) between successful heartbeat checks
of the peer.
560
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......