Solved

two sonicwalls / firewalls for failover, but not HA

Posted on 2013-01-03
8
933 Views
Last Modified: 2013-01-07
Greetings,

I have a sonicwall 240. they have been discontinued. can't find a 240 HA unit. can't afford a new 220 plus a 220 HA unit.

Is there a way to install another sonicwall (NSA 220, TZ model, etc.) into production with the 240 for a make-shift HA set up? Essentially, two firewalls set up with the same rules so if one goes down the other takes over, even if it is a manual failover by setting up a remote connection to each firewall and failing over as needed.

thanks
0
Comment
Question by:rpliner
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 11

Assisted Solution

by:rharland2009
rharland2009 earned 150 total points
ID: 38741673
I'd do this. If my core switch is layer 3, then you could turn on RIP on your Sonicwalls to advertise default routes from your Sonicwalls to your core switch. It's not the most elegant thing, but it would work. If you're not familiar with routing protocols, it might be a little tough - but this is a good place to start.
0
 
LVL 13

Assisted Solution

by:Ugo Mena
Ugo Mena earned 150 total points
ID: 38741678
It is feasible to get that particular setup working. However, the high availability (HA) service relies on a heartbeat synch between the Active and Idle firewalls. Since you cannot enable the HA service in dis-similar firewalls, you would need to setup both firewalls individually, then just disconnect the "backup". You can "disconnect" the firewall from the network in a variety of ways, based on what makes the most sense for your network's LAN & WAN IPs.
 
On failing, you would need to manually connect the backup firewall to your network.

The caveat with HA and any "active" backup firewall you setup is that if you have any subscription based add-ons like GAV/CFL/etc... you will need to purchase the same add-ons for the backup firewall or go without while that firewall is in service.
0
 
LVL 7

Author Comment

by:rpliner
ID: 38741709
thanks. I am going to check this out further.
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 13

Expert Comment

by:Ugo Mena
ID: 38741715
If you want to place both firewalls into active mode on your network, then you should make sure all of your machines are getting IPs assigned statically and then set both default gateways in the Advanced TCP/IP settings, adding manual Metric's for both.

TCP/IP by default automatically calculates an interface metric that is based on the speed of the interface. The interface metric becomes the metric of the default route in the routing table for the configured default gateway. The second default gateway should be used when the first is unavailable.
0
 
LVL 20

Accepted Solution

by:
carlmd earned 200 total points
ID: 38745043
Have you looked on ebay?

There is a number of NSA240 units for around $400.
0
 
LVL 7

Author Comment

by:rpliner
ID: 38748537
I only saw one 240 on eBay and it was about $1700. If you saw several, can you send a link to your eBay search or your search terms? I'm unable to see but that one.

I think I'm going to get approval to go about $500 over budget and get an NSA 220, an NSA 220 HA unit, and the HA license. Got a quote for $2175. That'll match what I have at the data center.

Thanks all
0
 
LVL 20

Expert Comment

by:carlmd
ID: 38748603
On ebay search nsa240.

Your quote seems high for the two NSA220's. Take a look on www.sonicguard.com
0
 
LVL 7

Author Comment

by:rpliner
ID: 38751596
Sonicguard.com ended up being more expensive based on their website.

Actually found a good one on eBay with support, services, and warranty through 04/2014 verified through SonicWall as the serial number was posted on eBay, which I then relayed to SonicWall for verification. Thanks for the search tip. I didn't look thoroughly enough when I first searched.

Thanks all for your help.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Slow Internet Connection 9 54
Hyper V - Create Virtual switch Hangs - pnpdrivernotfound 2 52
Vcenter 8 52
Vyos VLANs 14 36
Is your company's data protection keeping pace with virtualization? Here are 7 dynamic ways to adapt to rapid breakthroughs in technology.
In this article, I will show you HOW TO: Perform a Physical to Virtual (P2V) Conversion the easy way from a computer backup (image).
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question