Connection Synchronization
Connection synchronization overview
Connection synchronization is a feature that is used by the system to support high availability between two instances of vRouter running VRRP.
To support high availability, the firewall states must be synchronized between the master and backup routers. The connection synchronization feature is used by the system to perform this synchronization. When a backup router with VRRP becomes the master router, this feature initializes the firewall states in the new master.
Connection synchronization helps keep existing stateful connections going through the master and backup routers alive even after failover.
Configuring connection synchronization
This example shows how to configure connection synchronization between two vRouters that are configured by enabling the firewall and VRRP. The R1 vRouter is configured as the VRRP master router and the R2 vRouter is configured as the VRRP backup router.
When you complete the example, the interfaces are configured as shown in the following figure.
To configure the connection synchronization, you must configure the failover mechanism, interface, and remote peer for each router.
Perform the following steps on the R1 vRouter.
Step | Command |
---|---|
Assign an IP address directly to the dp0p192p1 untagged Ethernet interface. |
|
Assign an IP address directly to the dp0p224p1 untagged Ethernet interface. |
|
Configure the firewall for the dp0p224p1 interface. |
|
Configure the firewall for the dp0p192p1 interface. |
|
Configure VRRP for the dp0p224p1 interface. |
|
Assign an IP address to the dp0p256p1 interface. |
|
Configure the firewall. |
|
Configure the connection synchronization failover. |
|
Configure an IP address for the R2 vRouter as the remote peer. |
|
Configure SSH. |
|
Verify the connection synchronization configuration. |
|
Verify the configured interfaces. |
|
Verify entries in the session table. |
|
Verify entries in the internal cache table. |
|
Verify connection synchronization statistics. |
|
Perform the following steps on the R2 vRouter.
Step | Command |
---|---|
Assign an IP address directly to the dp0p192p1 untagged Ethernet interface. |
|
Assign an IP address directly to the dp0p224p1 untagged Ethernet interface. |
|
Configure the firewall for the dp0p224p1 interface. |
|
Configure the firewall for the dp0p192p1 interface. |
|
Configure VRRP for the dp0p224p1 interface. |
|
Assign an IP address to the dp0p256p1 interface. |
|
Configure the firewall. |
|
Configure the connection synchronization failover. |
|
Configure an IP address for the R2 vRouter as the remote peer. |
|
Configure SSH. |
|