Active-Passive Lab:
PA1 (Active) IP Schema
Outside Layer 3 Interface Ethernet1/1 – [Link]/24
Inside Layer 3 Interface Ethernet1/2 – [Link]/24
HA1 or Control Link Ethernet1/3 – [Link]/24
HA1 or Control Link Backup Ethernet1/4 – [Link]/24
HA2 or Data Link Ethernet1/5 – Layer 2
HA1 or Data Link Backup Ethernet1/6 – Layer 2
PA2 (Passive) IP Schema
Outside Layer 3 Interface Ethernet1/1 – [Link]/24
Inside Layer 3 Interface Ethernet1/2 – [Link]/24
HA1 or Control Link Ethernet1/3 – [Link]/24
HA1 or Control Link Backup Ethernet1/4 – [Link]/24
HA2 or Data Link Ethernet1/5 – Layer 2
HA1 or Data Link Backup Ethernet1/6 – Layer 2
LAN PC Details
LAN PC IP [Link]/24
LAN PC Default Gateway [Link]/24
LAN PC DNS [Link]
Firewall Management IP subnet [Link]/24
PA1-HA Ports:
We do not have any dedicated HA1 and HA2 primary and backup ports. So, we are going to
make ethernet1/3 as HA1, ethernet1/4 as HA1 backup, ethernet1/5 as HA2 and ethernet1/6 as
HA2 backup. To do this, go – Network >> Interface >> Ethernet. And, then need to change the
interface type to HA port.
Change the interface type for ethernet1/4 as HA port.
Change the interface type for ethernet1/5 as HA port.
Change the interface type for ethernet1/6 as HA port.
Finally, all four-interface type has been changed to HA mode.
PA1-Group Configuration:
Enable HA, add Group ID and put Peer HA1 IP Address. Below are the configuration of PA1
firewall. Select Device>>High Availability>>General and edit the Setup section.
Settings Description
Enable HA Activate HA functionality.
Group ID Enter a number to identify the HA pair (1 to 63).
Description Enter a description of the HA pair.
Mode Set the type of HA deployment: Active-Passive or Active-Active.
Device ID In active/active configuration, set the Device ID to determine which
peer will be active-primary (set Device ID to 0) and which will be
active-secondary (set the Device ID to 1).
Enable Config Sync To enable synchronization of configuration settings.
Peer HA1 IP Address Enter IP address of the HA1 interface of the peer firewall.
Backup Peer HA1 IP Enter IP address for the peer’s backup control link.
Address
PA1-Active-Passive Settings:
In Device>>High Availability>>General, edit the Active Passive Settings.
Settings Description
Passive Link State Select one of the following options to specify whether the data links on
the passive firewall should remain up.
auto The links that have physical connectivity remain physically up but in a
disabled state.
shutdown Forces the interface link to the down state. This is the default option,
which ensures that loops are not created in the network.
Monitor Fail Hold This value between 1-60 minutes determines the interval in which a
Down Time (min) firewall will be in a non-functional state before becoming passive.
PA1-Priority and Preemption:
Add device priority to prefer PA1 as Active unit. And also, preemption will be enabled to make
sure whenever PA1 firewall is up and running, it handles the traffic. The firewall with the lower
value will be Active and other firewall is Passive firewall. In Device>>High Availability>>General,
edit the Election Settings.
Settings Description
Device Priority Enter a priority value to identify the active firewall. The firewall with
the lower value (higher priority) becomes the active firewall (range is
0–255).
Preemptive Enables the higher priority firewall to resume active (active/passive)
or active-primary (active/active> operation after recovering from a
failure.
Heartbeat Backup Uses the management ports on the HA firewalls to provide a backup
path for heartbeat and hello messages.
HA Timer Settings Recommended: Use for typical failover timer settings.
Aggressive: Use for faster failover timer settings.
Advanced: Allows to customize values to suit network requirement.
PA1-Control Plane Configuration:
Go Device >> High Availability. Now, by clicking on top right gear icon in Control Link (HA1)
section, we will declare ethernet1/3 as our control plane link (HA1) as we decided earlier.
We will be using [Link]/24 for HA1 link. Below are the configuration of Active and Passive
nodes. It’s Point-to-Point, so we do not need any gateway here.
Settings Description
Port Select the HA port for the primary interfaces.
IPv4/IPv6 Address Enter the IPv4 or IPv6 address of the HA1 interface for the primary.
Netmask Enter the network mask for the IP address for the primary
Gateway Enter the IP address of the default gateway for the primary.
PA1-Control Plane Backup Configuration:
Go Device >> High Availability. Now, clicking on top right gear icon in Control Link (HA1 Backup)
section, we will declare ethernet1/4 as our control plane link (HA1 Backup) as we decided
earlier. We will be using [Link]/24 for HA1 backup link.
Settings Description
Port Select the HA port for the backup interfaces.
IPv4/IPv6 Address Enter the IPv4 or IPv6 address of the HA1 interface for backup.
Netmask Enter the network mask for the IP address for the Backup.
Gateway Enter the IP address of the default gateway for the backup.
PA1-Data Link Configuration:
On the same page Device >> High Availability, need to click on top right gear icon in Data Link
(HA2) section. In our case, ethernet1/5 is our HA2 link. It’s directly connected, so transport
mode is ethernet. Do not need to specify any IP address.
Settings Description
Enable Session Enable synchronization of the session information with the passive
Synchronization firewall and choose a transport option.
Port Select HA port Configure this setting for the primary HA2 interfaces.
IPv4/IPv6 Address Specify the IPv4 or IPv6 address of the HA interface for the primary.
Netmask Enter the network mask for the IP address for the Primary.
Gateway Enter the IP address of the default gateway for the primary.
Transport Ethernet: Use when the firewalls are connected back-to-back or
through a switch.
HA2 keep-alive If enabled, the peers will use keep-alive messages to monitor the HA2
connection to detect a failure based on the Threshold you set (default
is 10,000 ms).
Log Only Logs the failure of the HA2 interface in the system log as a critical
event.
Split Datapath this option in active/active HA deployments to instruct each peer to
take ownership of their local state and session tables when it detects
an HA2 interface failure.
Threshold (ms) The duration in which keep-alive messages have failed before one of
the above actions will be triggered
PA1-Data Link Backup Configuration:
On the same page Device >> High Availability, need to click on top right gear icon in Data Link
(HA2 Backup) section. In our case, ethernet1/6 is our HA2 backup link. It’s directly connected,
so transport mode is ethernet. Do not need to specify any IP address.
Settings Description
Port Select the HA port for the backup interfaces.
IPv4/IPv6 Address Enter the IPv4 or IPv6 address of the HA1 interface for backup.
Netmask Enter the network mask for the IP address for the Backup.
Gateway Enter the IP address of the default gateway for the backup.
PA1-Save Changes:
Click on top right corner Commit link to save the changes.
PA2-HA Ports:
Going to make ethernet1/3 as HA1, ethernet1/4 as HA1 backup, ethernet1/5 as HA2 and
ethernet1/6 as HA2 backup. To do this, go – Network >> Interface >> Ethernet. And, then need
to change the interface type to HA port.
Change the interface type for ethernet1/4 as HA port.
Change the interface type for ethernet1/5 as HA port.
Change the interface type for ethernet1/6 as HA port.
Finally, all four-interface type has been changed to HA mode.
PA2-Group Configuration:
Enable HA, add Group ID and put Peer HA1 IP Address. Below are the configuration of PA1
firewall. Select Device>>High Availability>>General and edit the Setup section.
PA2-Active-Passive Settings:
In Device>>High Availability>>General, edit the Active Passive Settings.
PA2-Priority and Preemption:
Add device priority to prefer PA1 as Active unit. And also, preemption will be enabled to make
sure whenever PA1 firewall is up and running, it handles the traffic. The firewall with the lower
value will be Active and other firewall is Passive firewall. In Device>>High Availability>>General,
edit the Election Settings.
PA1-Control Plane Configuration:
Go Device >> High Availability. Now, by clicking on top right gear icon in Control Link (HA1)
section, we will declare ethernet1/3 as our control plane link (HA1) as we decided earlier.
We will be using [Link]/24 for HA1 link. Below are the configuration of Active and Passive
nodes. It’s Point-to-Point, so we do not need any gateway here.
PA2-Control Plane Backup Configuration:
Go Device >> High Availability. Now, clicking on top right gear icon in Control Link (HA1 Backup)
section, we will declare ethernet1/4 as our control plane link (HA1 Backup) as we decided
earlier. We will be using [Link]/24 for HA1 backup link.
PA1-Data Link Configuration:
On the same page Device >> High Availability, need to click on top right gear icon in Data Link
(HA2) section. In our case, ethernet1/5 is our HA2 link. It’s directly connected, so transport
mode is ethernet. Do not need to specify any IP address.
PA2-Data Link Backup Configuration:
On the same page Device >> High Availability, need to click on top right gear icon in Data Link
(HA2 Backup) section. In our case, ethernet1/6 is our HA2 backup link. It’s directly connected,
so transport mode is ethernet. Do not need to specify any IP address.
PA2-Save Changes:
Click on top right corner Commit link to save the changes.
Verification:
To verify the HA status. Just go to Dashboard >> Widgets >> System >> High Availability.
You can see our Active-Passive HA is already formed. However, configuration doesn’t sync yet.
We can follow below to sync configuration from Active to Passive unit. We can just click on Sync
to peer. It will automatically sync configuration from Active unit to Passive unit.
Run this command will do the same job.
admin@PA-ACTIVE(active)> request high-availability sync-to-remote running-config
Only in Active Firewall:
Create Zones:
Configure two zones names Inside and Outside. Go to Network> Zone>Add, Give the name
Inside, select Type to be Layer3 and click OK. Create the same way other Zone Outside.
Configure Security Policy:
Now, create a Security Policy to allow access from Inside to Outside zone.
Policies>Security>Add, Give the name to your Security Policy (Inside-to-Outside), Add Source
Zone ( Inside), Add Destination Zone ( Outside), Allow access, in our case allowing all traffic.
Configure Interfaces:
Go to Network>Interfaces Click on ethernet1/1 interface change Interface Type: Layer3, set
Virtual Router: default, set Security Zone: Outside , Click on IPv4 tab Assign IP Address:
[Link]/24 and Click OK. Click on ethernet1/2 interface change Interface Type: Layer3,
set Virtual Router: default, set Security Zone: Inside , Click on IPv4 tab Assign IP Address:
[Link]/24.
Configure Routing:
Each interface must be given virtual router. Network>Virtual Router>default we will add default
routing. Static Routes>IPv4>Add we will go by choosing interface> ethernet1/1(as Outside), put
[Link] as the next hop due to our topology.
Configure NAT/PAT:
Let’s configure NAT using Dynamic IP and Port means translate all local LAN to only one IP
address. I will NAT my Inside LAN [Link]/24 to [Link] IP address of WAN.
Policies > NAT > Add Let’s name it Inside-To-Outside.
Verify which unit is currently active and which one is currently passive by using CLI command.
> show high-availability state
From WebGUI > Device > High Availability > Operational Commands - click Suspend local device
Verify that the firewall is now in a suspended state before a reboot and the passive member
assume the active position.
Inside of the WebGUI > Device > High Availability > Operational Commands - click on Make local
device functional