
Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Redundant Firewalls
127
213455-L, October 2005
The sync connection on port 2 supports stateful failover (see
Synchronizing Nortel Switched
Firewalls on page 186
for configuration details), which is optional for high-availability
networks.
Requirements
The installation of a redundant firewall is handled as an expansion that creates a Switched
Firewall cluster. The following conditions and equipment are required:
A Switched Firewall must be physically installed as described in
Nortel Switched Firewall
5100 Series Hardware Installation Guide
(216382-D)
.
The Switched Firewall must be
configured with basic parameters as described in
Chapter 2, Initial setup.
You must reinstall the software on the first Firewall, if you enabled the Check Point
SmartCenter Server on it during initial setup (see
Step 12
on
page 41
).
The
/cfg/net/vrrp/ha
feature must be disabled on the first firewall before you add
the second firewall. The
addr1
and
addr2
address for each interface must also be
configured on the first firewall before you add the second firewall.
N
OTE
–
If access lists are configured on the firewall#1, make sure that an access list entry for
firewall#2 is added on firewall#1, or add an access list entry for the SSI network.
You must be able to establish trust on both Switched Firewalls (see
Establishing trust on
redundant Firewalls on page 185
).
The redundant Switched Firewall must be
identical
to the existing Switched Firewall. You
cannot mix different models or software versions in the same cluster. For example, you
cannot mix a 5109 and 5114; but you can mix a 5109 and a 5111-NE1. Similarly, you can
mix a 5114 and a 5114-NE1.
A layer 2 switch or hub is required to provide redundant network feeds to both firewalls.
N
OTE
—
The switch or hub must have the ability to forward multicast packets.
!
C
AUTION
—
Any Switched Firewall being added must have the same version of Firewall OS as
the other Switched Firewall. See
Chapter 8, Upgrading and reinstalling the software,”
for more
information.
C
AUTION
—
Also, any Switched Firewall being added must be set to the factory default mode.
If moving a previously configured Switched Firewall from another system, you must first
delete the Firewall
from the old cluster to reset its configuration. For more information, see the
delete
command in the Firewall menu on
page 287
.
Содержание 5100 Series Release 2.3.3
Страница 18: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 18 Preface 213455 L October 2005...
Страница 20: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 20 Getting started 213455 L October 2005...
Страница 28: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 28 Introduction 213455 L October 2005...
Страница 90: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 90 Initial setup 213455 L October 2005...
Страница 188: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 188 Redundant Firewalls 213455 L October 2005...
Страница 228: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 228 Applications 213455 L October 2005...
Страница 248: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 248 Basic system management 213455 L October 2005...
Страница 250: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 250 Command reference 213455 L October 2005...
Страница 264: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 264 The Command Line Interface 213455 L October 2005...
Страница 374: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 374 Command reference 213455 L October 2005...
Страница 376: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 376 Appendices 213455 L October 2005...
Страница 406: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 406 Common tasks 213455 L October 2005...