
EQ/OS Version 10 Failover Constraints
Before you begin configuring failover, you must do the following:
1. Ensure that the VLAN configuration on both EQ/OS 10 Equalizer is
exactly
the same. This includes all
VLAN and subnet parameters
except
for the tagged and untagged ports assigned to a VLAN.
2. In some cases there may appear to be an issue where the Primary and Backup Equalizers are in a conflict
over Primary. Any switch, such as one from Cisco or Dell, that comes with Spanning Tree Protocol enabled
by default can cause a communication problem in a failover configuration. This problem occurs at boot up
because the switch disables its ports for roughly 30 seconds to listen to BPDU (Bridge Protocol Data Unit)
traffic. The 30 second pause causes both Equalizers to attempt to become the primary unit, and the default
backup continually reboots. To repair this condition, either disable Spanning Tree Protocol or enable
PortFast for the ports connected with the Equalizers. This enables the ports to act as normal hubs and
accept all traffic immediately.
3. When configuring VLAN subnets, the following must be true:
l the heartbeat flag must be enabled on
at least one
VLAN
l the command flag must be enabled on
exactly one
VLAN
l the Failover IP (virt_addr in the CLI) parameter must be set on all VLAN subnets that have
the heartbeat or command flags enabled
4. Other important notes:
l Run http on the failover IP address, not the VLAN IP address.
l Only make changes when logging in over the failover IP address.
l If you run GUI/SSH on the VLAN IP addresses on both peers, then do NOT go back and forth
between peers making configuration changes, unless you verify that each change is
transferred before you making a change on the “other” unit.
Configuration Synchronization Constraints
Whenever a configuration change is made on either EQ/OS 10 failover unit, the failover subsystem synchronizes
the configuration by transferring the configuration file to the other unit over the VLAN subnet that has the
command flag enabled.
If the command flag (Command Transfer in the GUI) is NOT set for any VLAN, the system will use the first VLAN
in the configuration file for Configuration transfer.
The table below lists the Equalizer objects that ARE and ARE NOT synchronized between units in a failover
configuration:
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
435
Equalizer Administration Guide
Kommentare zu diesen Handbüchern