
Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
126
Redundant Firewalls
213455-L, October 2005
Configuration overview
The network topology for a typical active-standby (high-availability) network with Switched
Firewalls is shown in
Figure 58
.
Figure 58
Active-Standby failover configuration
This example uses layer 2 switches to supply redundant feeds to the firewalls (hubs may also
be used for the same purpose). The default data path is through link3 and link4 since the VRRP
Election process (see
page 119
) default-designates the firewall with the higher IP address
(NSF#2 in this case) as the active master. If either link fails on the default path, the active
master will stop sending VRRP advertisements and transition both virtual routers into a fault
state. When the backup doesn't receive VRRP advertisements, it will initiate the VRRP
failover process (see
VRRP failover on page 120
) and assume the role of active master.