This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HA Active/passive Heartbeat sync issues.

Hello Everyone,

We are having an issue with our HA setup and am hoping to get a bit of help regarding this..

So we've had a physical firewall in for a while now and just recently it has started crashing randomly whereby we will have to hard reboot it.

 

Thinking HA is the way to go to solve this, we've bought new hardware and have attempted the heartbeat sync, an issue we have noticed is that the original Mac addresses for the NICs in the production UTM have synced to the new hardware thus stopping our connections from working as the new NICs have their own Mac addresses.

Is the solution to buy the same equipment for both units? Or is there a way we can alter the macs without the heartbeat re-syncing them.

 

Many Thanks as always..



This thread was automatically locked due to age.
Parents Reply Children
  • Here's the instruction list I provide for my customers:

    1. If needed, do a quick, temporary install so that the new device can download Up2Dates.
    2. Apply the Up2Dates to the same version as the current unit, do a factory reset and shutdown.
    3. On the current UTM in use, on the 'Configuration' tab of 'High Availability':
       a. Enable Hot-Standby
       b. Select eth3 as the Sync NIC
       c. Configure it as Node_1
       d. Enter an encryption key (I've never found a need to remember it)
       e. Select 'Enable automatic configuration of new devices'
       f. I prefer to use 'Preferred Master: None' and 'Backup interface: Internal'
    4. Cable eth3 to eth3 on the new device.
    5. Cable all of the other NICs exactly as they are on the original UTM.
    6. Power up the new device and wait for the good news. [;)]

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thank you as always, Bob. Will bear it in mind for when we get identical hardware to our upgraded FW :)