Dedicated HA communication
interfaces should be used over dataplane interfaces. HSCI interfaces
aren’t used for HA4. This allows separation of HA pair and cluster
session synchronization to ensure maximum bandwidth and reliability
for session syncing.
HA4 should be adequately sized if you use dataplane interfaces.
This ensures best effort session state synchronizing between cluster
members.
Best practice is to have a dedicated cluster network for the
HA4 communications link to ensure adequate bandwidth and non-congested,
low-latency connections between cluster members.
Architect your networks and perform traffic engineering to avoid
possible race conditions, in which a network steers traffic from the
session owner to a cluster member before the session is successfully
synced between the firewalls. Layer2 HA4 connections must have sufficient
bandwidth and low latency to allow timely synchronization between
HA members. The HA4 latency must be lower than the latency incurred
when the peering devices switch traffic between cluster members.
Architect your networks to minimize asymmetric flows. Session
setup requires one cluster member to see the complete TCP three-way
handshake.