Chapter 34 Device HA

Management Access

You can configure a separate management IP address for each interface. You can use it to access the ZyWALL for management whether the ZyWALL is the master or a backup. The management IP address should be in the same subnet as the interface IP address.

Synchronization

Use synchronization to have a backup ZyWALL copy the master ZyWALL’s configuration, signatures (anti-virus, IDP/application patrol, and system protect), and certificates.

"Only ZyWALLs of the same model and firmware version can synchronize.

Otherwise you must manually configure the master ZyWALL’s settings on the backup (by editing copies of the configuration files in a text editor for example).

Finding Out More

See Section 5.4.8 on page 115 for related information on these screens.

See Section 34.8 on page 587 for device HA background/technical information.

See Section 6.9 on page 162 for an example of using device HA.

34.1.3Before You Begin

Configure a static IP address for each interface that you will have device HA monitor.

"Subscribe to services on the backup ZyWALL before synchronizing it with the master ZyWALL.

Synchronization includes updates for services to which the master and backup ZyWALLs are both subscribed. For example, a backup subscribed to IDP/AppPatrol, but not anti- virus, gets IDP/AppPatrol updates from the master, but not anti-virus updates. It is highly recommended to subscribe the master and backup ZyWALLs to the same services.

34.2 Device HA General

The Device HA General screen lets you enable or disable device HA, and displays which device HA mode the ZyWALL is set to use along with a summary of the monitored interfaces.

576

 

ZyWALL USG 100/200 Series User’s Guide