7 Menu Network
Securepoint 10
Securepoint
Security Solutions
48
7.2.1.6 Add Cluster Interface
The cluster interface is needed to set up a high availability environment.
Two (or more) appliances are required to adjust this setup. One appliance acts in active state
as master and the other appliances are waiting in stand-by mode as spare. If important ser-
vices cannot be provided by the active machine or the whole machine breaks down, the oth-
er appliance wakes op from stand-by and assumes the service as master.
The cluster interface binds a virtual and a “real” IP-address to a physical interface. The espe-
cialness of the high availability bond is that all appliances get the same virtual IP-addresses.
Because the redundant machines are running in standby mode and their cluster IPs are not
up, there will be no IP-addres
s conflict. The “real” IP-addreses (so called management IPs)
are used to send advertisement packages in terms of their status between the appliances.
DSL-modem
switch A
external net
switch C
DMZ
switch B
internal net
master
spare
eth2
192.168.13.1/24
192.168.13.2/24
eth2
192.168.13.3/24
192.168.13.2/24
eth1
192.168.4.86/24
192.168.4.88/24
eth1
192.168.4.87/24
192.168.4.88/24
eth0
10.0.0.1/24
10.0.0.2/24
eth0
10.0.0.3/24
10.0.0.2/24
internet
local net
red IP-address
à
management IP (real IP)
blue IP-address
à
cluster IP (virtual IP)
fig. 48 high availibility environment