- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-01-2023 08:57 PM - edited 06-01-2023 09:02 PM
HA1 is used to synchronize config and send heart beats. This is task of management plane so if firewall don't have dedicated HA1 port then it is best practice to use management interface for HA1.
HA2 is used to synchronize session table. Session table is on data plane. You can use any data port for HA2.
If you need only 7 ports and can use 1 for HA2 then it is perfect setup.
If you don't have any available data ports to use for HA2 then you can use only 1 link between firewalls - mgmt port for HA1.
But in this case passive firewall has no idea of session table and if you fail over then all clients loose their active sessions and need to rebuild (not user friendly :)).