Configuration is done via:
Configuration β High Availability
π οΈ Requirements for a Stable HA Setup
Two identical gateways with:
-
A valid license
-
The same firmware version
-
Static IP addresses for both gateways (do not use DHCP!)
-
A virtual IP address (VIP) that is freely available in the network
(Test availability in advance viaping
orarp-scan
) -
A shared SHA1 secret for mutual authentication between gateways
π Step-by-Step Configuration
1οΈβ£ Prepare Both Gateways
-
Open the web interfaces of both devices in separate browser tabs.
-
Under Configuration β Network:
-
Assign a static IP address
-
Set subnet mask and default gateway
-
Save and restart both devices
-
2οΈβ£ Configure HA Settings
In Configuration β High Availability on both devices:
-
β Enable HA (check the box)
-
π§ Enter the virtual IP address (VIP)
β Ensure the VIP is not in use elsewhere on the network! -
π§© Enter the network mask to match your IP setup
-
π Set the SHA1 secret
β Must be identical on both devices!
π§ Define Roles:
-
On the master device: Enable βMasterβ checkbox
-
On the slave device: Leave βMasterβ unchecked
π Peer Configuration:
-
Enter the IP address and hostname of the other gateway
-
Click Save
3οΈβ£ Restart Both Gateways
-
Reboot both gateways via the web interface
-
Wait until both devices are fully reachable
π Function Test
-
In your browser, test the following:
-
The individual IP addresses of both gateways
-
The virtual IP address (VIP)
-
π Test Failover
-
Manual switchover is only possible via the VIP
-
Test functionality using:
β Manual Cluster Failover
β The system should automatically switch roles (Master β Slave)
π€ Optional: Transfer Configuration to the Second Gateway
If you prefer configuring only one gateway:
-
Export the configuration
(via web GUI or shell) -
Import it to the slave gateway
β οΈ Manual adjustments are required:
-
π§Ύ Change the IP address
-
π₯οΈ Adapt the hostname
-
π Re-enter the HA settings manually
π§ Important: HA settings are not transferred during import!
Manual reconfiguration is absolutely necessary!
β οΈ Troubleshooting β If Something Goes Wrong
π« Gateway Unreachable / Bootloop?
-
Try accessing the device via console (SSH or direct terminal)
-
If not possible:
-
Disconnect power for 1β2 minutes
-
Reconnect and check again
-
π Apache Web Server in Restart Loop?
-
Check if the local IP conflicts with the VIP
-
If unsure: Reset to factory defaults
π‘ Tips for Stable HA Operation
-
Never use DHCP β Always use a static network configuration
-
Set up an NTP time server
β Time differences disrupt HA communication -
Regularly verify consistency across both gateways:
β Users, rules, services must stay in sync -
Optional: Set up automated config backups
Comments
0 comments
Please sign in to leave a comment.