版權說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權,請進行舉報或認領
文檔簡介
1、Active/Active High AvailabilityPAN-EDU-205PAN-OS 6.1Rev BAgendaActive-Passive HA OverviewActive/Active HA ConceptsActive/Active HA Deployment OptionsConfiguring Active/Active HA2Active/Passive HA OverviewHA1Active/Passive HA Overview If the Passive Device loses connection to the Active Device, it ca
2、nnot distinguish between a down peer device and a communication problemIf the Active Device loses connection to the Passive Device, the path and link monitoring will not be honored as the Active Device doesnt know that the peer will take overXHA24Active/Active HA ConceptsActive/Active HA Introductio
3、nDevices back each other, taking over primary ownership if the other one failsBoth devices in the cluster are:Actively processing and passing trafficLoad-sharing the trafficNo increase in session capacityNot designed to increase throughputVirtual wire and layer 3 modes onlyActive/Active6Link to pass
4、 packets between Session Owner and Session Setup devicesActive/Active HA LinksActive PathActive PathHA2HA1HA3Active-PrimaryActive-SecondaryData Plane link to Sync Active SessionsControl Plane link to Sync Configuration7Assigning Session Ownership for a New SessionPacket arrives at one of the devices
5、Receiving device has no session for the packet, and assumes ownership of the sessionComputed hash/modulo determines if the Session-Owner is responsible for the Session SetupSession Owner00101000101010010018Assigning Session Setup for a New SessionPacket arrives at one of the devicesReceiving device
6、has no session for the packet, and assumes ownership of the sessionComputed hash/modulo determines if Session Owner is responsible for Session SetupIf not, Session Owner forwards packet to peer device over HA3 linkSession is Setup and session info and packet are returned to Session OwnerSession Owne
7、r forwards packet out appropriate interface0010100010101001001Session OwnerSession Setup 9Packet Flow in an Established SessionPacket arrives at one of the devicesReceiving device has session for the packet and owns the sessionPacket is processed and sent out via the appropriate egress interface0010
8、100010101001001Session Owner10Asymmetric Flow in an Established Session Packet arrives at one of the devicesReceiving device has a session for the packet but it is owned by the peer deviceReceiving device forwards the packet over the HA3 link to the owner for processingOwner processes the packet Pac
9、ket is returned to receiver*Firewall forwards the packet out appropriate interface0010100010101001001Session Owner*Virtual Wire deployments only 11Active/Active HA Deployment OptionsDeployment Topologies OverviewIntranetThe design of the Active/Active HA deployment needs to address three main design
10、 considerations:Firewall addresses presented to the networksFirewall involvement in routing Achieving seamless failoverIntranetInternet 13Virtual Wire Deployment No IP or MAC address on the up and down linksOnly basic HA configuration requiredIntranetInternet 14Floating IP Deploymenteth1/1- 172.35.2
11、.252FIP-172.35.2.101HA1HA2HA3172.35.2.4GW: 172.35.2.101172.35.2.3GW: 172.35.2.100eth1/1- 172.35.2.253FIP-172.35.2.100 dev-id 0dev-id 1FIP-172.35.2.100XFloating IP addresses and virtual MAC addresses move between devices on failoverSupports VPN and NAT implementationsCan use external load balancers t
12、o spread traffic across devices15Device High Availability Active/Active ConfigFloating IP Configurationeth1/1- 172.35.2.252FIP-172.35.2.101HA1HA2HA3172.35.2.4GW: 172.35.2.101172.35.2.3GW: 172.35.2.100eth1/1- 172.35.2.253FIP-172.35.2.100 dev-id 0dev-id 1eth1/2- 10.1.1.253FIP-10.1.1.100 eth1/2- 10.1.1
13、.252FIP-10.1.1.101 16ARP Load-Sharing DeploymentA single IP address is shared between devicesUnique MAC address for each interface supporting the shared IP addressDevices respond to client ARP requests based on source IP addressRequires a Layer 2 connection deviceeth1/1- 172.35.2.25200:1B:17:00:AF:0
14、1HA1HA2HA3172.35.2.4GW: 172.35.2.101172.35.2.3GW: 172.35.2.101eth1/1- 172.35.2.25300:1B:17:00:8F:01dev-id 0dev-id 1172.35.2.101If a router were here, ARP Load-Sharing would not work. 17Combined Deploymenteth1/1- 172.35.2.25200:1B:17:00:AF:01HA1HA2HA3172.35.2.0/24GW: 172.35.2.101eth1/1- 172.35.2.2530
15、0:1B:17:00:8F:01dev-id 0dev-id 1172.35.2.101eth1/2- 10.1.1.253FIP-10.1.1.100 eth1/2- 10.1.1.252FIP-10.1.1.101 Floating IP address and ARP Load-Sharing deployments can be combined in a single implementationInternet 18Route Based Redundancy Deployment Leverages dynamic routing protocols for failover a
16、nd load balancingAll interfaces have unique, static IP address for use by the routing protocolVR sync must be disabled in the HA configuration/28/28/28/28BGP19Configuring Active/Active HADevice and Group IDUniquely identifies a Device within an HA ClusterDevice High Availability General Setup21Elect
17、ion SettingsDevice High Availability General Election SettingsDetermines primary and secondary devices mendedMust be enabled on both firewalls22HA1 Link ConfigurationDevice High Availability General Control Link (HA1)Only encrypts HA1 link info23HA2 Link ConfigurationDevice High Availability General
18、 Data Link (HA2)Required for stateful synchronization across HA2 link24HA3 InterfaceForwards packets for Session Setup and Layer 7 processingDevice High Availability Active/Active ConfigSynchronizes Zones, Routing, and VR configuration if enabledIf disabled, no virtual IP shared between firewalls25HA Virtual AddressesDevice High Availability Active/Active ConfigTwo Types Available26Active/Activ
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經(jīng)權益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責。
- 6. 下載文件中如有侵權或不適當內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 家庭急救教育從知識到實踐
- 2025年度環(huán)??萍既肼殕T工保密及保密技術協(xié)議2篇
- 二零二五年度現(xiàn)代化農(nóng)業(yè)用地租賃合同范本2篇
- 2024生鮮冷鏈物流配送合同3篇
- 2025年度物流運輸入股分紅合作協(xié)議范本2篇
- 2024水產(chǎn)品冷鏈配送與市場購銷合作協(xié)議3篇
- 2025年度河道整治土方工程買賣合同協(xié)議
- 辦公空間人性化設計及裝修策略研究
- 2024版股東聯(lián)合經(jīng)營協(xié)議模板詳解版B版
- 2024新款車輛租賃與VIP客戶關懷合同3篇
- COPD(慢性阻塞性肺病)診治指南(2023年中文版)
- 氣相色譜儀作業(yè)指導書
- ?中醫(yī)院醫(yī)院等級復評實施方案
- 跨高速橋梁施工保通專項方案
- 鐵路貨車主要輪對型式和基本尺寸
- 譯林版南京學校四年級英語上冊第一單元第1課時storytime導學單
- 理正深基坑之鋼板樁受力計算
- 員工入職培訓
- 鋪種草皮施工方案(推薦文檔)
- 10KV高壓環(huán)網(wǎng)柜(交接)試驗
- 綜合單價的確定
評論
0/150
提交評論