Control Link (HA1)/Control Link (HA1 Backup) | The firewalls in an HA pair use HA links
to
synchronize data and maintain state information. Some firewall
models have a dedicated Control Link and dedicated backup Control
Link; for example, PA-5200 Series firewalls have HA1-A and HA1-B. In
this case, you should enable the Heartbeat Backup option in the
Elections Settings. If you're using a dedicated HA1 port for the
Control Link HA link and a data port for Control Link (HA Backup),
it's recommended that you enable the Heartbeat Backup option. For firewalls that don't have a dedicated HA port, such as the PA-220 firewall, you should
configure the management port for the Control Link HA connection and
a data port interface configured with type HA for the Control Link
HA1 Backup connection. Because the management port is used in this
case, there is no need to enable the Heartbeat Backup option because
the heartbeat backups will already occur through the management
interface connection. On the VM-Series firewall
in AWS, the management port is used as the HA1 link.
When using a data port for the HA control link,
keep in mind that because the control messages have to communicate from
the dataplane to the management plane, if a failure occurs in the
dataplane, peers cannot communicate HA control link information
and a failover will occur. It is best to use the dedicated HA ports,
or on firewalls that do not have a dedicated HA port, use the management
port.
|