D-Link NetDefend DFL-210 User Manual page 295

Network security firewall
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

11.3.3. Verifying Cluster Functioning
This device is an HA MASTER
This device is currently ACTIVE (will forward traffic)
HA cluster peer is ALIVE
Then use the stat command to verify that both master and slave have about the same number of
connections. The output should contain a line similar to this:
Connections 2726 out of 128000
where the lower number is the current number of connections and the higher number is the
connections limit of the license.
The following points are also relevant to cluster setup:
If this is not the first cluster in a network then the advanced setting ClusterID must be changed
to have a unique value (the default is 0). This makes sure the MAC address for the cluster is
unique.
Enabling the advanced setting HAUseUniqueSharedMacAddressPerInterface is also
recommended so that each interface has its own MAC address. If this is not enabled, interfaces
share a MAC address and this can confuse some switches.
Make sure that the advanced setting HighBuffers is set to automatic on all units in a cluster.
This setting allocates memory for handling connections.
Where a cluster has tens of thousands of simultaneous connections then it may be necessary to
set a value above the automatic value. Much higher values have the disadvantage of possibly
increasing thoughput latency.
295
Chapter 11. High Availability

Advertisement

Table of Contents
loading

Table of Contents