When the Master-Role changes within a Cluster PPPoE Connections will go down until the admin manually restarts the connection or until the automatic reconnect occurs.
It would be helpful if an PPPoE Interface has an Option to trigger the reconnect when Cluster-Roles change.12 votes
This was treated as a bug and was fixed in Version 8.300. I’ll close this feature as a result.
For safety, instead of forcing the admin to disconnect and put a node to the side for "safekeeping" in case of a big failure when upgrading, it should be possible to set a node as "reserved" during the up2date process so that it remains separate and can instantly become active while the other unit(s) are upgraded.
This lets the admin get back online and buys some breathing room in case they need to re-image or otherwise work with their cluster to address a failure.10 votes
This feature has been completed and is ready for testing in the current Sophos UTM 9 Beta version which can be found at http://www.astaro.org/beta-versions/utm-9-public-beta/
Thx Astaro PM Team
Zero Downtime for VPN and network WAN connection in a HA setup.14 votes
This feature has been in the system for a while. In the interest of good feature hygene, I’ll mark this as completed. HA failover is near instant, and stateful for non-proxied traffic, including VPN connections. (this should also have been the case when this feature was entered, however) If the failure is not the ethernet cable directly connected to the port, however, there will necessarily be some delay in detecting upstream failure, before the firewall can react.
"Watch Up2Date progress in new window" will not work in HA or cluster environments, right? Would be very nice to see though, as Up2Date progress of slave is kind of mysterious otherwise...2 votes
We have added the ability to see from the status page the current status of the attached cluster units and give you feedback during Up2Date operations.
Per RFC 2663 , section 4.4 (IP NAT Terminology), allow ASG to link to another ASG to allow increase in performance. Since HA already handles redundancy the only addition would be to put the backup ASG device to use to improve performance.
Idea is to share state between each box (already in HA), and also allow each box to perform NAT/rule services for an internal network(s). This would increase performance and redundancy (already in HA).
This is already possible using an active active cluster, which supports up to Ten units in the manner you describe.
During the bootup of a cluster, there is a 15 minute wait period where a failover cannot occur, while the cluster sets itself up and syncs. It should be noted during the status of the cluster that this is occuring. Keeps administrators informed that currently no failover will be possible due to cluster bootup/sync operations.5 votes
This has been completed in V7.500
Show multiple appliance images in WebAdmin to reflect the status of a cluster by visualizing the connected appliances with a graphical display.. provides a good visual overview to the admin of a connected cluster / ha setup.2 votes
Provide a way to view the serial number of all connected units in an HA or clustering setup in the dashboard/licensing sections.. GIves the admin the ability to find the serial numbers of his connected units without going to the command line, causing a failover, or having to manually go look.1 vote
- Don't see your idea?