This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Changing from 2 SG430's to a Active-Active Cluster

We currently run a pretty inefficient WAN design, with each site having its own internet connection, and a UTM at each, with IPSec VPNs running back to our central site.

I am considering changing this to a different design - basically all our edge sites will be connected by P2P ethernet back to the central site, and that site will have a central breakout.

We currently own 2 x SG 430, 1 x SG 330, 1 x SG 310 and 1 x SG 230.

Looking at the load on all the devices, they are massively under utilised, so I don't have any worries about load on the SG 430s, but my question is this - will we be able to put those 2 SG 430's into an Active-Active HA configuration without changing any licensing? They are both fully licensed until next year (only missing Sandstorm and Endpoint Protection).

Would I need to buy some form of cluster license?



This thread was automatically locked due to age.
  • You would cut the remaining time of your licensing in half, Tony.

    The only reason to use Active-Active would be because a single 630 wasn't powerful enough for you.  Otherwise, Active-Passive (AKA Hot-Standby) is the most cost-effective solution.

    Failover happens in less time than a ping in either case - no time would be gained with Active-Active.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA