To be able to configure a high availability cluster between two managed firewalls, both must be in the same cluster on the Control Center. Managed high availability clusters only share the same virtual server configuration; the box level of both firewalls are configured individually. Use cluster level repositories to share the box level configurations between both units. The two firewalls receive their configurations directly from the Control Center; the HA session sync is carried out directly between the two firewalls. You can only combine two firewalls of the same model and platform (hardware, virtual, or public cloud). Using different revisions of the same hardware appliance is supported.
Before You Begin
- In a cluster, select two firewalls of the same model and platform E.g., two Barracuda CloudGen Firewall F280RevB
- Verify that the cabling is done exactly the same on both units. The management IP addresses must also be configured on the same ports. For HA clusters using hardware appliances with different revisions, only use ports present on both systems.
- License and activate both firewalls
Step 1. Complete the Box Level Configuration for both CloudGen Firewalls
The box level configuration for both firewalls must be identical, except for the Network, Box Properties and Licensing pages. If the connection to the Control Center is over a public IP address each firewall must also have a public IP address configured on the box layer. Use repository links for easy maintenance of the other configuration pages. For more information, see Repositories.
Step 2. Assign a Primary and Secondary Unit for the Virtual Server
Choose which firewall is by default the active unit in the HA cluster. For active-active clusters, repeat this step for the second virtual server.
- Go to your cluster in the Control Center > Virtual Servers > your virtual server > Server Properties.
- Click Lock.
- In the Virtual Server Definition section, define the primary unit and secondary unit.
- Primary Box – The active system.
- Secondary Box – The HA partner.
The primary and secondary servers are created and configured as HA partners on both units.