Trend Micro™ Network VirusWall™ Enforcer 2500 Administrator’s Guide
1
-
30
Failover Considerations
Consider the following points when implementing a failover solution:
•
A Network VirusWall Enforcer 2500 failover pair must have identical
devices—same model and running the same Network VirusWall Enforcer 2500
program file and boot loader. Otherwise, the failover solution cannot work.
•
Check whether the switches connected to the Network VirusWall Enforcer 2500
devices have Spanning Tree Protocol (STP) enabled.
•
If STP is not enabled and there is a Network VirusWall Enforcer 2500 failover
pair in the network, Network VirusWall Enforcer 2500 will send heavy UDP
traffic broadcasts.
•
Network VirusWall Enforcer 2500 disables failopen (LAN bypass) in a failover
environment.
•
Do not automatically update the program file for the devices in a failover pair.
Doing so alters the identical settings for the failover devices, which consequently
disconnects the failover link.
Failopen
The failopen or LAN bypass solution involves one Network VirusWall Enforcer 2500
device. Failopen is a fault-tolerance solution that allows the Network VirusWall
Enforcer 2500 device to continue to pass traffic in an event when a software or
hardware failure occurs within the device.
In addition to previously supported cards, this release of Network VirusWall Enforcer
2500 supports 10/100/1000M copper, Sx fiber, and Lx fiber cards that also support
link-state failover.
Applying a failopen solution requires the completion of the following tasks:
1.
Establishment of Network VirusWall Enforcer 2500 connection to other network
devices
2.
Enable failopen