Join the Conversation

To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".

SonicWALL Active/Active Cluster - Multiple gateway

ediredir Newbie
edited July 2020 in Mid Range Firewalls

We have 2 firewalls in Active-Active mode, and now we are trying to understand how can we configure the load balance between two gateways.

Do I have to choose what equipment the traffic will go through?

Does someone have any example of configuring this part? I mean of the switch configuration. [policy based routes on a downstream router]

šŸ˜«šŸ™„

Category: Mid Range Firewalls
Reply

Best Answer

Answers

  • SaravananSaravanan Moderator

    Hi @EDIR,

    Thank you for contacting SonicWall Community.

    The load balancing between the two gateways can be achieved using a static route defined on the downstream device such as a L3 Switch or a Router. Since the SonicWall appliances are in Active-Active cluster, you should be using two virtual groups for each interfaces configured on SonicWall. Let me take X0 as an example, we should see X0 IP - Virtual Group 1 and X0 IP - Virtual Group 2 objects in the address objects section. We are going to use one of these objects as the default gateway in the route that would be defined in the downstream device.

    This makes the downstream device to force the traffics via standby cluster unit to achieve load balancing.

    Hope this helps. Please let us know if any questions. We would be happy to answer.

    Regards

    Saravanan V

    Technical Support Advisor - Premier Services

    Professional Services

  • ediredir Newbie

    If i'am using just one default gateway, i'll not being really using the active-active feature

    We would like so see a configuration (in switch) which shows these routes or PBR.

  • SaravananSaravanan Moderator

    Hi @EDIR,

    The Active - Active by default offers, Hardware Failover and Load Balancing only with offloading DPI inspection from active (Master) firewall to idle (Slave) firewall. Therefore we are trying to share the network load with the slave unit as well and making slave to be part of the active state. In your case, if you want to dedicate some network traffic to pass via the slave unit, you have to define the route on the downstream device as explained previously. I have seen this working flawlessly.

    Regards

    Saravanan V

    Technical Support Advisor - Premier Services

    Professional Services

Sign In or Register to comment.