524
High availability and load balancing using clusters
Updating interfaces in a cluster configuration
Using stateful failover to maintain cluster connections
Stateful failover lets you maintain connections even after a security gateway fails in a cluster
environment. The HA/LB feature maintains connections without reconnecting or reauthorizing as
long as the connection was active for 60 seconds prior to the failure. This option only affects the
following type of TCP traffic: HTTP/HTTPS, Telnet, FTP, TCP-GSP, and TCPAP-GSP. You configure
stateful failover in a rule.
Note:
The security gateway supports FTP file transfer using a Web browser (commonly referred to as
FTP conversion). Stateful failover for FTP protocol conversion is not supported when the Web browser
is configured to proxy the security gateway. Stateful failover is supported for all other FTP client
methods.
Prerequisites
None.
To use stateful failovers to maintain cluster connections
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, select the rule that you want to modify to use stateful failover, and then click
Properties
.
3
In the Rule’s Properties dialog box, on the Miscellaneous tab, check
Stateful failover
.
4
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the tool bar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
None.
Updating interfaces in a cluster configuration
When you add or remove interfaces from your cluster members, or when you change an interface, such
as updating the netmask, you must update your cluster configuration information with these changes.
The SGMI automatically detects interface changes and prompts you to update the system and cluster
configuration.
Note:
Network interface changes must be made to all cluster members using the System Setup Wizard
before they can be updated in the cluster configuration.
There are three scenarios where you may want to update interfaces in a cluster configuration:
■
Adding a network interface to a cluster member
■
Removing a network interface from a cluster member
■
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...