534
High availability and load balancing using clusters
Backing up and restoring cluster configurations
Rebooting cluster members that are in hot standby mode
When you reboot the members of a cluster that are in hot standby mode, the reboot sequence is
important. For example, when you install hotfixes on the members of a cluster that are configured in
hot standby mode, you must always use the following reboot sequence.
Prerequisites
None.
To reboot cluster members that are in hot standby mode
1
With the active cluster member in control and the standby cluster member waiting, reboot the
active cluster member.
All traffic fails over to the standby cluster member.
2
When the active cluster member has started, stop the standby cluster member.
This routes all traffic back to the active cluster member.
3
Reboot the standby cluster member.
Related information
None.
Configuring gateway-to-gateway VPN tunnels that use NAT
When you use NAT to configure a gateway-to-gateway VPN tunnel in a cluster, you must configure the
address transform that you use by specifying the tunnel rather than <ANY VPN> as the entering and
leaving values. If you configure more than one address transform using <ANY VPN> it is likely to
confuse the cluster settings. Before you configure a gateway-to-gateway tunnel, be aware that the
security gateway does not support multicast in a cluster environment.
Backing up and restoring cluster configurations
From an administrator’s point of view, there is no difference between a standalone and a cluster
backup operation. The system information that is backed up for a cluster includes:
■
Interface information
■
Location settings
■
Policy
■
Global cluster information such as VIPs and monitored processes.
Note:
You must create a password when you create your backup file, and use it when you restore the
backup file, or your restore will fail.
When a cluster configuration is restored, the cluster ID, heartbeat interface, and member information
are not restored. This allows a cluster image to be restored onto any active cluster, independent of
cluster membership differences, such as the number of members.
You can restore a cluster backup image either on a standalone system or a member of the cluster. The
cluster related information is not restored on a standalone system. You have the option of restoring
cluster information for VIPs, process monitoring, failover timeouts, traffic groups, and ping groups
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...