Overview
174
Nokia IP60 Security Appliance User Guide
Note:
You can force a fail-over to a passive IP60 appliance. You may want to do this
in order to verify that HA is working properly, or if the active IP60 appliance needs
repairs. To force a fail-over, switch off the primary box or disconnect it from the LAN
network.
The IP60 appliance supports configuring multiple HA clusters on the same network segment. To this end,
each cluster must be assigned a unique ID number.
When HA is configured, you can specify that only the Active Gateway in the cluster should connect to the
Internet. This is called WAN HA, and it is useful in the following situations:
Your Internet subscription cost is based is on connection time, and therefore having the Passive
appliances needlessly connected to the Internet costs you money.
You want multiple appliances to share the same static IP address without creating an IP address
conflict.
WAN HA avoids an IP address change, and thereby ensures virtually uninterrupted access from the Internet
to internal servers at your network.
On the other hand, you might prefer to keep Passive Gateways connected to the Internet at all times, so that
they can download updates from the Service Center and be accessible for remote management, even when
not acting as the Active Gateway. In this case, you must assign a virtual IP address to the WAN interface.
Each Passive Gateway will remain constantly connected to the Internet using its WAN interface's primary
IP address, while remaining on standby to take over the WAN virtual IP address, in the event that the
Active Gateway fails. If desired, you can configure a WAN virtual IP address for the WAN2 interface, as
well.
Note:
To use a WAN virtual IP address, the Internet connection method must be
"Static IP". PPP-based connections and dynamic IP connections are not supported.
Before configuring HA, the following requirements must be met:
You must have at least two identical IP60 appliances.
The appliances must have identical firmware versions and firewall rules.
The appliances' internal networks and bridges must be the same.
The appliances must have
different
real internal IP addresses, but share
the same
virtual IP
address.
The appliances' synchronization interface ports must be connected either directly, or via a hub or
a switch. For example, if the DMZ is the synchronization interface, then the DMZ/WAN2 ports
on the appliances must be connected to each other.
The synchronization interface need not be dedicated for synchronization only. It may be shared with an
active internal network or bridge.
You can configure HA for the WAN interface, for any bridge, and for any internal network except wireless
networks and the OfficeMode network.
Note:
You can enable the DHCP server in all IP60 appliance
s. A Passive Gateway’s
DHCP server will start answering DHCP requests only if the Active Gateway fails.
Summary of Contents for IP60 - Security Appliance
Page 1: ...Part No N450000643 Rev 001 Published February 2008 Nokia IP60 Security Appliance User Guide ...
Page 4: ...4 Nokia IP60 Security Appliance User Guide ...
Page 10: ......
Page 12: ......
Page 38: ......
Page 58: ......
Page 108: ......
Page 268: ......
Page 482: ......