Experience with Active/Active Clustering on Sonicwall NSA Firewalls

Does anyone have any experience with running a pair of SonicWall's in an Active/Active Configuration?

We are thinking of adding another unit to make a pair to add extra performance with our new internet connection while adding some redundancy.

Does it work well?
How is the failover/failback?
Do you get close to the combined throughput of both units?
Any gotchas?
LVL 1
PerimeterITAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Aaron TomoskySD-WAN SimplifiedCommented:
Can you please describe your current setup including model numbers and bandwidth information? Also which security packages on the sonicwall you use and any other firewall/Ids/gav/etc devices.
0
PerimeterITAuthor Commented:
We have a pair of NSA 3500's with the HA license.
Its for a 1gb/s sync internet connection, expecting 2500 simultaneous connections.

This is a temporary project, and throughput is essential. We have disabled IPS and all scanning functionality. Security wise we are happy with a basic firewall/NAT.
0
Aaron TomoskySD-WAN SimplifiedCommented:
I assume you have see this:
http://www.sonicwall.com/downloads/SonicOS_5.6.5_Active-Active_Clustering.pdf

My personal experience doesn't get into active active clusters but I will say that sonicwall performance is 1/2 of stated in all cases I've experienced e.g. if it can handle 500mbps up and 500mbps down they state that as 1gbps.
The isd throughput is also 1/2 again (so 1/4 of stated)  in default high/medium/low threat detection. To get back up to 1/2 of stated you have to switch to "performance mode" which doesn't look for low value threats.

Anyway the point of all this is You may not get 1gbps up and down even with two 3500s in a cluster.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.