Configure your active/passive HA deployments using HAVIP.
| Where Can I Use This? | What Do I Need? |
- Alibaba Cloud International Regions subscription
- Alibaba Cloud Mainland China subscription
|
- VM-Series License (BYOL)
- VM-Series plugin
- Panorama
|
The VM-Series firewall on Alibaba Cloud now supports
active/passive HA deployments using a new feature of Alibaba cloud called HAVIP.
The
HAVIP listens to the ARP/GARP messages
sent by the VM-Series firewalls to determine which network interfaces belong to the
active VM-Series firewall, and then forward traffic to those
interfaces.
The HAVIP deployment architecture consists of two HAVIP interfaces and two VM-Series
firewalls that are configured in active/standby HA mode.
One of the HAVIPs is configured with a public IP address (external HAVIP). The
Untrust interface of each VM-Series firewall is bound to this
external HAVIP. The other HAVIP (internal HAVIP) does not have an attached public IP
address. The Trust interface of each VM-Series firewall is bound to
the internal HAVIP.
In this example, the External HAVIP is in the same subnet as the Untrust interfaces,
while the Internal HAVIP is in the same subnet as the Trust interfaces.
The HAVIP address must be in the same subnet as the network interfaces
that are bound to it.
Subnets in Alibaba Cloud can't span multiple zones, so this solution will
only work if both VM-Series firewalls are in the same
availability zone.