Failover
Perform Steps 4 and 5 on the preferred primary Equalizer to add failover flags and to create a new peer
definition for the backup.
You now need to configure the preferred primary Equalizer by adding failover flags and creating a
peer on it for the backup that you created in steps 3 and 4. You will need the peer signature from
the backup that you retained in step 4.
4. Log in to the Equalizer you will designate as the preferred primary and do the following:
a. Display the peer name of the preferred primary by entering:
eqcli
show peer
------------------------------------
Configuration Sequence Number: 4593
------------------------------------
Peer Name
Type
Flags
F/O Mode
Error?
eq_001D7D78E13E (local) OS/10
xfr
Standalone
No
Flags Key:
F/O=> failover
A/A=> active-active
P/P=> preferred_primary
xfr=> fo_config_xfer
ssl => use_ssl
eqcli >
b. Assign failover,
peferred_primary
flags to the preferred primary Equalizer by
entering:
eqcli >
peer
name
flags failover,preferred_primary,fo_config_xfer
c. Verify that the flags are correct by entering the
show peer
command again to
display the peer (preferred primary). The flags should display
F/O, P/P, xfr
beneath the
Flags
heading. The
fo_config_xfer
is used on the local peer and
not on the remote peer. If it is enabled the primary peers on both systems will
synchronized the configuration. When the flag is changed for the local peer, it
should be reflected in the remote peer on the other system.
When the use_ssl flag is set, it causes messages from this Peer to a remote Peer to be transmitted
using SSL. When not set, messages are transmitted in clear text.
The flag may be set differently for Peers in failover. For example, if set on Peer A, but not set on Peer
B, heartbeats from Peer A to Peer B will be encrypted, however, heartbeats from Peer B to Peer A
WILL NOT be. Also, a configuration synchronization request from Peer A to Peer B will be encrypted
and so the response (Peer B's configuration) will also be encrypted. A configuration synchronization
request, and the response, from Peer B to peer A will not be encrypted.
All transfers between a Peer that supports this flag and an older Peer that does not are done without
using SSL, regardless of the setting of the flag on the Peer that supports it.
564
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......