Solved

two sonicwalls / firewalls for failover, but not HA

Posted on 2013-01-03
8
929 Views
Last Modified: 2013-01-07
Greetings,

I have a sonicwall 240. they have been discontinued. can't find a 240 HA unit. can't afford a new 220 plus a 220 HA unit.

Is there a way to install another sonicwall (NSA 220, TZ model, etc.) into production with the 240 for a make-shift HA set up? Essentially, two firewalls set up with the same rules so if one goes down the other takes over, even if it is a manual failover by setting up a remote connection to each firewall and failing over as needed.

thanks
0
Comment
Question by:rpliner
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 11

Assisted Solution

by:rharland2009
rharland2009 earned 150 total points
ID: 38741673
I'd do this. If my core switch is layer 3, then you could turn on RIP on your Sonicwalls to advertise default routes from your Sonicwalls to your core switch. It's not the most elegant thing, but it would work. If you're not familiar with routing protocols, it might be a little tough - but this is a good place to start.
0
 
LVL 13

Assisted Solution

by:Ugo Mena
Ugo Mena earned 150 total points
ID: 38741678
It is feasible to get that particular setup working. However, the high availability (HA) service relies on a heartbeat synch between the Active and Idle firewalls. Since you cannot enable the HA service in dis-similar firewalls, you would need to setup both firewalls individually, then just disconnect the "backup". You can "disconnect" the firewall from the network in a variety of ways, based on what makes the most sense for your network's LAN & WAN IPs.
 
On failing, you would need to manually connect the backup firewall to your network.

The caveat with HA and any "active" backup firewall you setup is that if you have any subscription based add-ons like GAV/CFL/etc... you will need to purchase the same add-ons for the backup firewall or go without while that firewall is in service.
0
 
LVL 7

Author Comment

by:rpliner
ID: 38741709
thanks. I am going to check this out further.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 13

Expert Comment

by:Ugo Mena
ID: 38741715
If you want to place both firewalls into active mode on your network, then you should make sure all of your machines are getting IPs assigned statically and then set both default gateways in the Advanced TCP/IP settings, adding manual Metric's for both.

TCP/IP by default automatically calculates an interface metric that is based on the speed of the interface. The interface metric becomes the metric of the default route in the routing table for the configured default gateway. The second default gateway should be used when the first is unavailable.
0
 
LVL 20

Accepted Solution

by:
carlmd earned 200 total points
ID: 38745043
Have you looked on ebay?

There is a number of NSA240 units for around $400.
0
 
LVL 7

Author Comment

by:rpliner
ID: 38748537
I only saw one 240 on eBay and it was about $1700. If you saw several, can you send a link to your eBay search or your search terms? I'm unable to see but that one.

I think I'm going to get approval to go about $500 over budget and get an NSA 220, an NSA 220 HA unit, and the HA license. Got a quote for $2175. That'll match what I have at the data center.

Thanks all
0
 
LVL 20

Expert Comment

by:carlmd
ID: 38748603
On ebay search nsa240.

Your quote seems high for the two NSA220's. Take a look on www.sonicguard.com
0
 
LVL 7

Author Comment

by:rpliner
ID: 38751596
Sonicguard.com ended up being more expensive based on their website.

Actually found a good one on eBay with support, services, and warranty through 04/2014 verified through SonicWall as the serial number was posted on eBay, which I then relayed to SonicWall for verification. Thanks for the search tip. I didn't look thoroughly enough when I first searched.

Thanks all for your help.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question