- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
09-14-2021 08:42 AM - edited 09-14-2021 08:43 AM
Hello everyone
We have configured active-passive HA on a pair of 5220
I have configured link monitoring
I need to migrate the HA links of the FW , all except the backup HA1 management one.
What would be the best procedure to prevent them from becoming active?
Is there any way to check end to end after each change, apart from looking at the link up????
I am thinking making the passive node non-funcional but I'm not sure.
Thanks
09-14-2021 02:36 PM
Thank you for posting question @Alpalo
Personally, I would suggest to suspend Firewall you will be working on by going to High Availability > Operational Commands > Suspend local device. I would also recommend to disable Preemption under: High Availability > General > Election Settings. This will give you a control which device will be active regardless of configured priority.
Regarding checking after processing each step, I would recommend to go to CLI and issue: show high-availability interface <HA Interface Name>, then make sure you see bytes received and transmitted. By issuing this command multiple times, you will see statistics to be increasing for bytes received and transmitted to make sure basic connectivity is there.
Note: HA configuration is not synchronized between Firewalls, so you will have to make sure that HA configuration is consistent across both Firewalls.
Kind Regards
Pavel
09-14-2021 02:36 PM
Thank you for posting question @Alpalo
Personally, I would suggest to suspend Firewall you will be working on by going to High Availability > Operational Commands > Suspend local device. I would also recommend to disable Preemption under: High Availability > General > Election Settings. This will give you a control which device will be active regardless of configured priority.
Regarding checking after processing each step, I would recommend to go to CLI and issue: show high-availability interface <HA Interface Name>, then make sure you see bytes received and transmitted. By issuing this command multiple times, you will see statistics to be increasing for bytes received and transmitted to make sure basic connectivity is there.
Note: HA configuration is not synchronized between Firewalls, so you will have to make sure that HA configuration is consistent across both Firewalls.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!