Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
146
Redundant Firewalls
213455-L, October 2005
Figure 65
is a diagram of an active-active failover configuration.
Figure 65
Active-active failover configuration
In
Figure 65
, the network configuration uses separate routers and separate layer 7 switches to
supply separate data feeds for the firewall hosts. The synchronization connection on port 2
supports stateful failover (see
Synchronizing Nortel Switched Firewalls on page 186
for
configuration details).
Firewall NSF#1 is the master for the virtual IP address 200.1.1.100 (ip1) on port 4 and backs
up the virtual IP address 200.1.1.200 (ip2) on port 4. Firewall NSF#2 is the master for virtual
IP address IP 200.1.1.200 (addr2) on port 4 and backs up virtual IP address IP 200.1.1.100