D-Link DFL-2500 User Guide - Page 326

Planning the High Availability cluster, Creating a High Availability cluster

Page 326 highlights

29.3. Setting up a High Availability Cluster 307 The topics below describe the operations required to setup a complete High Availability cluster. 29.3.1 Planning the High Availability cluster As an example throughout this guide, two D-Link Firewalls are used as cluster members. To simplify this guide, only two of the interfaces on each cluster member are used for network traffic. The following setup is used: • The LAN interfaces on the cluster members are both connected to the same switch. This switch resides on an internal network with IP addresses from the 192.168.10.0/24 network. • The WAN interfaces on the cluster members are both connected to a second switch. This switch resides on an external network with IP addresses from the 10.4.10.0/24 network. • The IP addresses for the interfaces are designated as indicated by this table: Interface Shared IP address Master IP address Slave IP address LAN 192.168.10.1 192.168.10.2 192.168.10.3 WAN 10.4.10.1 10.4.10.2 10.4.10.3 • The DMZ interfaces on the cluster members are used for state synchronization, and therefore connected to each other using a crossover Ethernet cable. 29.3.2 Creating a High Availability cluster Example: Configuring the Firewall as a Cluster Member Each firewall in the cluster will have to be configured to act as either a HA master or slave. This includes configuration of private (master and slave) and shared IP addresses on interfaces, as well as selecting a cluster ID and synchronization interface. D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

29.3. Setting up a High Availability Cluster
307
The topics below describe the operations required to setup a complete High
Availability cluster.
29.3.1
Planning the High Availability cluster
As an example throughout this guide, two D-Link Firewalls are used as
cluster members. To simplify this guide, only two of the interfaces on each
cluster member are used for network traffic. The following setup is used:
The LAN interfaces on the cluster members are both connected to the
same switch. This switch resides on an internal network with IP
addresses from the 192.168.10.0/24 network.
The WAN interfaces on the cluster members are both connected to a
second switch. This switch resides on an external network with IP
addresses from the 10.4.10.0/24 network.
The IP addresses for the interfaces are designated as indicated by this
table:
Interface
Shared IP address
Master IP address
Slave IP address
LAN
192.168.10.1
192.168.10.2
192.168.10.3
WAN
10.4.10.1
10.4.10.2
10.4.10.3
The DMZ interfaces on the cluster members are used for state
synchronization, and therefore connected to each other using a
crossover Ethernet cable.
29.3.2
Creating a High Availability cluster
Example
:
Configuring the Firewall as a Cluster Member
Each firewall in the cluster will have to be configured to act as either a HA
master or slave. This includes configuration of private (master and slave)
and shared IP addresses on interfaces, as well as selecting a cluster ID and
synchronization interface.
D-Link Firewalls User’s Guide