freeGuard 100 CLI User Manual
205
responds to a failure. However, you can increase the heartbeat
lost threshold if repeated failovers occur because cluster
unitscannot sent heartbeat packets quickly enough.
hb-interval
<interval_integer>
The heartbeat interval, which is the time between sending
heartbeat packets. The heartbeat interval range is 1 to 20
(100*ms).
A heartbeat interval of 2 means the time between heartbeat
packets is 200 ms. Changing the heartbeat interval to 5
changes the time betweenheartbeat packets to 500 ms.
The HA heartbeat packets consume more bandwidth if the hb-
interval is short. But if the hb-interval is very long, the cluster is
not as sensitive to topology and other network changes.
2
hbdev <interface-
name_str>
<priority_integer>
Enable or disable HA heartbeat communication and set the
heartbeat priority for each interface in the cluster.
By default HA heartbeat is set for two interfaces. You can
disable the HA heartbeat for either of these interfaces or enable
HA heartbeat for other interfaces. In most cases you can
maintain the default hbdev configuration as long as you can
connect the hbdev interfaces together.
Enter all of the names and heartbeat priorities for the interfaces
to be configured. If you want to remove an interface from the list
or add an interface to the list, you must retype the list with the
interface and its priority removed or added.
The cluster units use the ethernet interfaces configured with HA
heartbeat priorities for HA heartbeat communication. The HA
heartbeat communicates cluster session information,
synchronizs the cluster configuration, synchronizes the cluster
routing table, andreports individual cluster member status. The
HA heartbeat constantly communicates HA status information to
make sure that the cluster is operating properly.
The heartbeat priority range is 0 to 512. The interface with the
highest priority handles all of the heartbeat traffic. If this
interface fails or becomes disconnected, the interface with the
next highest priority handles all of the heartbeat traffic.
You can enable heartbeat communications for physical
interfaces, but not for VLAN subinterfaces.
Enabling the HA heartbeat for more interfaces increases
reliability. If an interface fails, the HA heartbeat can be diverted
to another interface. HA heartbeat traffic can use a considerable
amount of network bandwidth. If possible, enable HA heartbeat
traffic on interfaces only used for HA heartbeat traffic or on
interfaces connected to less busy networks.
Heartbeat communication must be enabled on at least one
interface. If heartbeat communication is interrupted the cluster
stops processing traffic.
WAN1: 50
DMZ: 100
Содержание freeGuard 100
Страница 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Страница 3: ......
Страница 7: ......
Страница 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Страница 183: ...176...
Страница 309: ...302 100 from a TFTP server with the address 192 168 21 54 set vpn certificates local import branch_cert 192 168 21 54...