Failover
Issue 4 May 2005 227
Note:
Note: If the public-backup interface idle timer is disabled, the security gateway
continues to use the alternate network interface.
Network path failure is defined as the configured number of consecutive connectivity checks
without a response from the number of hosts that need to fail. The following is an example of a
network path failure criteria.
The configuration is as follows:
The number of consecutive “no” responses is five.
The idle time between each connectivity check is 10 seconds
The number of hosts to monitor is three.
The number of hosts that must fail to respond, out of the hosts configured is two.
Tab le 17 shows which hosts respond (Y) and which hosts do not respond (N) during the
10-second interval connectivity check.
The network path failure criteria are met only when both hosts 2 and 3 concurrently fail to
respond five times (at the 130 second mark) to the connectivity checks. Hos t 3 fail ed to re spond
five consecutive times (between the 10-second interval and the 50-second interval). Host 2
failed to respond five consecutive times (between the 50-second interval and the 90 second
interval). But only when host 2 and host 3 both fail to respond to the same five consecutive
security checks are the failure criteria met.
To configure failover:
1. From the VPNmanager Console main window, select Failover as a New Object. The
Failover tab appears.
2. From the Failover>Contents column select the device to configure for Failover.
3. Select Enable to provide an alternate network path to re-establish access to the cent ral-sit e
resources.
Table 17: Failover connectivity checks in 10-second intervals
10 20 30 40 50 60 70 80 90 100 110 120 130
Host
1 YYYNNNYYYY Y Y Y
2 YYYYNNNNNN N N N
3 NNNNNYYYNN N N N