
Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Redundant Firewalls
145
213455-L, October 2005
Configuring VRRP active-active failover
The network topology for a typical active-active network with Switched Firewalls is shown in
Figure 65
. The following topics are addressed in this section:
Configuration overview on page 126
Requirements on page 147
Installing the redundant Switched Firewall on page 147
Configuration check list on page 147
Configuring the redundant Switched Firewall on page 148
Configuring Check Point software on page 148
Configuration dump for VRRP active-active failover on page 154
Configuration overview
An active-active configuration is similar to a active-standby configuration (see
Configuring
VRRP active-standby failover on page 125
) with the following differences:
Two real IP addresses (addr1 and addr2) are required on each interface.
/cfg/net/if #/addr2 on one firewall host must be configured with same network as
/cfg/net/if #/addr1 on the opposite firewall host.
Only symmetric routing is supported. For example, when a SYN packet passes through
firewall
firewall NSF#1
, the server should return the SYN ACK packet to the firewall
firewall NSF#1
gateway. If the SYN ACK happens to reach firewall
NSF#
2, it is dropped.
Active-active solutions are dependant on GARP messages to update ARP caches.
External
devices must not block GARP messages
.