background image

High Availability Guide

iii

 Hudson ([email protected]).

© 1995-1998 Eric Young ([email protected])

 All rights reserved.

 This package is an SSL implementation written by Eric Young ([email protected]).

 The implementation was written so as to conform with Netscapes SSL.

 This library is free for commercial and non-commercial use as long as the following conditions are aheared to.  The 

following conditions apply to all code found in this distribution, be it the RC4, RSA, lhash, DES, etc., code; not just the 

SSL code.  The SSL documentation included with this distribution is covered by the same copyright terms except that 

the holder is Tim Hudson ([email protected]). 

Copyright remains Eric Young's, and as such any Copyright notices in the code are not to be removed. If this package is 

used in a product, Eric Young should be given attribution as the author of the parts of the library used. This can be in 

the form of a textual message at program startup or in documentation (online or textual) provided with the package. 

Redistribution and use in source and binary forms, with or without modification, are permitted provided that the 

following conditions are met:

 1. Redistributions of source code must retain the copyright notice, this list of conditions and the following disclaimer.

 2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following 

disclaimer in the documentation and/or other materials provided with the distribution.

 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: 

"This product includes cryptographic software written by Eric Young ([email protected])" The word 'cryptographic' 

can be left out if the routines from the library being used are not cryptographic related :-).

 4. If you include any Windows specific code (or a derivative thereof) from the apps directory (application code) you 

must include an acknowledgement: "This product includes software written by Tim Hudson ([email protected])"

 THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, 

INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 

FOR A PARTICULAR PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS 

BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 

DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 

LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 

THEORY OF LIABILITY, 

WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 

ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 

SUCH DAMAGE.

 The licence and distribution terms for any publicly available version or derivative of this code cannot be changed.  i.e. 

this code cannot simply be copied and put under another distribution licence [including the GNU Public Licence.]

The mod_ssl package falls under the Open-Source Software label because it's distributed under a BSD-style license. 

The detailed license information follows.

Copyright (c) 1998-2001 Ralf S. Engelschall. All rights reserved.

Redistribution and use in source and binary forms, with or without modification, are permitted provided that the 

following conditions are met:

1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following 

disclaimer. 

2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following 

disclaimer in the documentation and/or other materials provided with the distribution.

3. All advertising materials mentioning features or use of this software must display the following acknowledgment:

"This product includes software developed by Ralf S. Engelschall <[email protected]> for use in the mod_ssl 

project (http://www.modssl.org/)."

4. The names "mod_ssl" must not be used to endorse or promote products derived from this software without prior 

written permission. For written permission, please contact [email protected].

5. Products derived from this software may not be called "mod_ssl" nor may "mod_ssl" appear in their names without 

prior written permission of Ralf S. Engelschall.

6. Redistributions of any form whatsoever must retain the following acknowledgment: "This product includes software 

developed by Ralf S. Engelschall <[email protected]> for use in the mod_ssl project (http://www.modssl.org/)."

 

THIS SOFTWARE IS PROVIDED BY RALF S. ENGELSCHALL ``AS IS'' AND ANY EXPRESSED OR IMPLIED 

WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY 

AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL RALF S. 

ENGELSCHALL OR HIS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, 

Содержание Firebox V10

Страница 1: ...WatchGuard Firebox Vclass High Availability Guide High Availability for Vcontroller 5 0 and CPM 4 1...

Страница 2: ...ademarks of Sun Microsystems Inc in the United States and other countries All right reserved 1995 1998 Eric Young eay cryptsoft All rights reserved 1998 2000 The OpenSSL Project All rights reserved Re...

Страница 3: ...INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES LOSS OF USE DATA OR PROFITS OR BUSINESS INTERRUPTION HOWEVER CAU...

Страница 4: ...d Apache Software Foundation must not be used to endorse or promote products derived from this software without prior written permission For written permission please contact apache apache org 5 Produ...

Страница 5: ...bility System 3 Connecting the appliances 4 Installing High Availability 4 Configuring High Availability Active Active in Vcontroller 7 Managing High Availability 13 Setting and Responding to Alarms 1...

Страница 6: ...vi High Availability for Vcontroller and CPM...

Страница 7: ...nd running a High Availability HA Active Active system using two Firebox Vclass appliances in a primary and secondary relationship This chapter discusses the following topics How High Availability Wor...

Страница 8: ...mum uptime and network availability Active Standby is available for all models that have an HA interface In this mode both appliances are configured with the same system name IP address and configurat...

Страница 9: ...must be reset to the factory default configuration Software upgrade licenses for the High Availability feature You obtain these licenses from the WatchGuard LiveSecurity web site after you register yo...

Страница 10: ...erfaces with crossover cables Connect the management station to a hub that is connected to interface 0 private on both appliances The management station can also be connected to an HA2 port Installing...

Страница 11: ...n here pending further info Import the Feature Key to the Vclass appliances To add the new license for the High Availability feature follow these steps 1 Click the License tab The Licences list is dis...

Страница 12: ...License This imports the license into the Firebox Vclass appliance After the import is complete the window closes and the newly imported license appears in the license list 6 Repeat this process to i...

Страница 13: ...tive Features The Active Features window appears 2 Review the active features along with their capacity and status 3 Click Refresh to update the feature list 4 When you are finished click Close Config...

Страница 14: ...High Availability for Vcontroller and CPM 2 After starting the WatchGuard Vcontroller click the System Configuration button 3 When the System Configuration window appears click the High Availability t...

Страница 15: ...the appliance s interfaces will be monitored If any interface is detected as LINK DOWN the Secondary appliance will take over The HA heartbeat interval is set to one beat every second The HA Group ID...

Страница 16: ...or better performance leave the HA secret blank This shared secret is used to encrypt HA state sync information VPN tunnel information is always encrypted even if this encryption is disabled 7 Change...

Страница 17: ...arameters You can customize a number of HA parameters using the Advanced HA Parameters dialog box At this level you can configure the following Send the HA heartbeat to the secondary appliance s HA2 m...

Страница 18: ...e HA2 interface that interface cannot be used for management access 6 If specific IP addresses have been assigned to the HA ports type the IP addresses and Netmasks in each of the two HA Interface fie...

Страница 19: ...System Failures When an appliance fails the other active appliance takes over processing When you log into the active appliance using Vcontroller check the System Status in the lower left corner to de...

Страница 20: ...em fails an Event alarm is generated and the failover process is logged in the event log You can check the alarms and the event log to determine when the failover occurred Make sure that you open and...

Страница 21: ...Setting and Responding to Alarms High Availability Guide 15 For more information on defining alarms see the Firebox Vclass User Guide and CPM User Guide...

Страница 22: ...16 High Availability for Vcontroller and CPM...

Страница 23: ...in CPM To set up the CPM Client to manage an HA Active Active connection 1 Log on to the CPM Client 2 Click Configuration Editor The Configuration Editor window appears 3 Right click an appliance reco...

Страница 24: ...feature is optional and can be left blank if you do not need to encrypt information sent between these appliances during normal operation Encryption is not necessary if the HA1 interfaces are connect...

Страница 25: ...pliance to monitor 12 Click the checkbox to select the HA interface you want to enable and send HA heartbeats over and type the Primary IP address Secondary IP address and Netmask of the HA interface...

Страница 26: ...new 1 Add HA licenses to both appliances 2 Reset both appliances to the factory default configuration 3 Add an appliance record for the primary appliance and set up the system with the proper HA conf...

Страница 27: ...s the secondary appliance 1 Add HA licenses to both appliances 2 Reset the new secondary appliance to factory defaults 3 Modify the system configuration of the primary appliance to enable HA and recom...

Страница 28: ...22 High Availability for Vcontroller and CPM...

Отзывы: