?
Solved

two sonicwalls / firewalls for failover, but not HA

Posted on 2013-01-03
8
Medium Priority
?
948 Views
Last Modified: 2013-01-07
Greetings,

I have a sonicwall 240. they have been discontinued. can't find a 240 HA unit. can't afford a new 220 plus a 220 HA unit.

Is there a way to install another sonicwall (NSA 220, TZ model, etc.) into production with the 240 for a make-shift HA set up? Essentially, two firewalls set up with the same rules so if one goes down the other takes over, even if it is a manual failover by setting up a remote connection to each firewall and failing over as needed.

thanks
0
Comment
Question by:rpliner
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 11

Assisted Solution

by:rharland2009
rharland2009 earned 600 total points
ID: 38741673
I'd do this. If my core switch is layer 3, then you could turn on RIP on your Sonicwalls to advertise default routes from your Sonicwalls to your core switch. It's not the most elegant thing, but it would work. If you're not familiar with routing protocols, it might be a little tough - but this is a good place to start.
0
 
LVL 13

Assisted Solution

by:Ugo Mena
Ugo Mena earned 600 total points
ID: 38741678
It is feasible to get that particular setup working. However, the high availability (HA) service relies on a heartbeat synch between the Active and Idle firewalls. Since you cannot enable the HA service in dis-similar firewalls, you would need to setup both firewalls individually, then just disconnect the "backup". You can "disconnect" the firewall from the network in a variety of ways, based on what makes the most sense for your network's LAN & WAN IPs.
 
On failing, you would need to manually connect the backup firewall to your network.

The caveat with HA and any "active" backup firewall you setup is that if you have any subscription based add-ons like GAV/CFL/etc... you will need to purchase the same add-ons for the backup firewall or go without while that firewall is in service.
0
 
LVL 7

Author Comment

by:rpliner
ID: 38741709
thanks. I am going to check this out further.
0
Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

 
LVL 13

Expert Comment

by:Ugo Mena
ID: 38741715
If you want to place both firewalls into active mode on your network, then you should make sure all of your machines are getting IPs assigned statically and then set both default gateways in the Advanced TCP/IP settings, adding manual Metric's for both.

TCP/IP by default automatically calculates an interface metric that is based on the speed of the interface. The interface metric becomes the metric of the default route in the routing table for the configured default gateway. The second default gateway should be used when the first is unavailable.
0
 
LVL 20

Accepted Solution

by:
carlmd earned 800 total points
ID: 38745043
Have you looked on ebay?

There is a number of NSA240 units for around $400.
0
 
LVL 7

Author Comment

by:rpliner
ID: 38748537
I only saw one 240 on eBay and it was about $1700. If you saw several, can you send a link to your eBay search or your search terms? I'm unable to see but that one.

I think I'm going to get approval to go about $500 over budget and get an NSA 220, an NSA 220 HA unit, and the HA license. Got a quote for $2175. That'll match what I have at the data center.

Thanks all
0
 
LVL 20

Expert Comment

by:carlmd
ID: 38748603
On ebay search nsa240.

Your quote seems high for the two NSA220's. Take a look on www.sonicguard.com
0
 
LVL 7

Author Comment

by:rpliner
ID: 38751596
Sonicguard.com ended up being more expensive based on their website.

Actually found a good one on eBay with support, services, and warranty through 04/2014 verified through SonicWall as the serial number was posted on eBay, which I then relayed to SonicWall for verification. Thanks for the search tip. I didn't look thoroughly enough when I first searched.

Thanks all for your help.
0

Featured Post

Percona Live Europe 2017 | Sep 25 - 27, 2017

The Percona Live Open Source Database Conference Europe 2017 is the premier event for the diverse and active European open source database community, as well as businesses that develop and use open source database software.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Suggested Courses
Course of the Month10 days, 15 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question