
S W G U s e r G u i d e
115
Chapter 19: Performing Additional Configuration Tasks
Passive Policy Server.
In the event of failure of the Active Policy Server, SWG automatically fails over to the secondary
Policy Server, making it the primary Active Policy server.
When the failed server can again be used, SWG designates it as the Passive Policy server. To switch
it back to being the Active policy server, you must manually perform the change using the Limited
Shell command
failover
. For more information on Limited Shell commands, see the
Management
Console
Reference
Guide
.
Â
To implement High Availability
1. Select
Administration
Æ
S
ystem
Settings
Æ
M86
Devices
.
2. In the Device tree that is displayed in the left pane, right‐click the
Management
Devices
Group
node and choose
Add
HA
Device
.
3. In the main window, fill in the mandatory Device IP, and optionally fill in a description. Note that
the device type is automatically set to Passive Policy Server.
4. Click
Save
.
5. Optionally, specify a virtual device IP, which will automatically route to whichever Policy Server is
active at any given time, as follows:
a. In the tree pane, select
Management
Devices
Group
.
b. In the main window, specify a virtual Device IP and click
Save
.
6. To complete implementation of the High Availability, including synchronization of the database
and configuration files, click
.
Modifying LDAP Directory Advanced Settings
Â
To modify Advanced LDAP settings
1. Select
Users
Æ
Authentication
Directories
Æ
LDAP.
2. In the tree, under the type of LDAP server, select the LDAP directory.
3. In the LDAP Directory definition screen, display the
Advanced
tab.
NOTE:
Implementation
of
High
Availability
requires
that:
• Your
Active
primary
and
secondary
Policy
Server
be
on
its
own
device,
NOT
on
an
All
In
one
device.
• The
device
that
will
house
the
secondary
Passive
Policy
Server
is
accessible
and
that
you
know
its
IP
address.
To
be
able
to
use
a
virtual
IP
address
which
will
automatically
route
to
the
Active
Policy
Sever
see
Step 5
,
both
Policy
Servers
must
be
on
the
same
network.
NOTE:
The
Management
Console
GUI
does
not
work
on
the
Passive
Policy
server
device.