Configuring FirePass Failover Servers and Cluster Servers
FirePass
™
Server Administrator Guide
7 - 5
Using FirePass server clusters
FirePass 4000 servers (or failover pairs of servers) can be clustered to
support many concurrent connections on a single logical URL without
performance degradation. Load balancing distributes the sessions among the
available servers to maximize throughput.
Each server (or failover pair) in the cluster must have a valid certificate and
be publicly accessible from outside the LAN using its own unique
fully-qualified domain name.
The master node distributes configuration updates (for example, available
system resources, new authorized users, and current user access rights) to
the slaves, once per minute. This synchronization allows any slave to service
any user session.
Clustered servers do not share session information. Each session is
established with a single server.
The master server in a cluster balances the load among slaves by redirecting
sessions to slaves. To make this possible, the slaves report their number of
currently active sessions as a part of the synchronization process.
You cannot change some configuration settings on slave servers. These
changes must be made on the master, so they are replicated across all slaves
during synchronization. When you use the Administration Console to
connect to a slave server, the configuration options that you cannot change
in slave servers are not available. For example, you cannot change user and
group account information in the slave servers, and consequently the Users
tab is not displayed when you connect to a slave server. To make global
configuration changes to a cluster, always connect to the master server. The
configuration information flows from the master to the slaves.
Installing multiple FirePass servers as a cluster
To connect several FirePass servers as a cluster, connect the primary NICs
to the same subnet unless they are installed in different geographic
locations.
Powering up FirePass server clusters
Whenever you power up the server cluster, always power up the master
server first. If the master server is not available when the slave servers
power up, then the cluster does not work properly.
Summary of Contents for FirePass
Page 1: ...FirePassTM Server Administrator Guide version 4 0 MAN 0081 00 ...
Page 2: ......
Page 4: ...ii ...
Page 5: ...Table of Contents ...
Page 6: ......
Page 12: ......
Page 18: ...Chapter 1 1 6 ...
Page 20: ......
Page 44: ...Chapter 2 2 24 ...
Page 46: ......
Page 82: ...Chapter 3 3 36 ...
Page 84: ......
Page 124: ......
Page 156: ...Chapter 5 5 32 ...
Page 158: ......
Page 168: ......
Page 177: ...Index ...
Page 178: ......