Before you begin
- By design, the configuration of the primary Sensor is copied to the secondary Sensor, overwriting the original configuration on the secondary. If you intend to configure both Sensors as fail-closed or fail-open, you need to configure the ports on the Sensor you intend to designate as the primary during the HA pair creation. However, if you intend to have one Sensor as fail-closed and the other as fail-open, you must revisit the Physical Ports page of each Sensor after creating the HA pair and make the appropriate changes.
- When using a copper SFP, make sure to change the Media Type of the port to Copper in the Physical Ports page before creating the HA pair.
- Ensure failover (interconnect cable) is connected between the Sensor pair before creating the HA pair.
You can create a HA pair using Device Manager page. A HA pair creation happens in real time; there is no need to explicitly update the configuration. To create a HA pair, perform the following steps:
Task
-
Go to
Devices → <Admin Domain Name> → Global → Device Manager.
The Device Manager page is displayed.
-
Select the
HA Pairs tab and click
.
.jpg)
The New HA Pair details panel is displayed. -
Enter the name of HA pair that uniquely identifies the grouping in
HA Pair Name.
Both Sensors in a HA pair must use same model and same version.
- Configure the Primary Sensor as Template Sensor from the drop-down option.
- Configure the Secondary Sensor as Peer Sensor from the drop-down option.
-
Enable or disable the
Disable Monitoring Ports on Link Failure as required. By default, it is disabled.
Enabling this option enables the ability of monitoring ports to permit fail-open configuration. It signifies your intent on whether to prioritize transport over security or prioritize no-network-disruption over traffic monitoring by IPS.
Trellix recommends one of the following:
- Enabled fail-open configuration:
- However, configure the monitoring ports on the primary Sensor as Inline Fail Closed so that they do not fail-open but indicate primary Sensor failure. This causes upstream traffic to be routed to the secondary Sensor thereby continuing traffic monitoring.
- Additionally, configure the monitoring ports on the secondary Sensor as Inline Fail Open so that, in case both Sensors have failed, traffic bypasses the HA pair.
- Disabled fail-open configuration:
- This ensures that the primary Sensor will not fail-open in case of a failure.
- Nevertheless, configure the monitoring ports on the primary Sensor as Inline Fail Closed so that they do not fail-open but indicate primary Sensor failure. This causes upstream traffic to be routed to the secondary Sensor thereby continuing traffic monitoring.
- Additionally, explicitly configure the monitoring ports on the secondary Sensor as Inline Fail Open so that, in case both Sensors have failed, traffic bypasses the HA pair.
- Enabled fail-open configuration:
-
Click
Save.
A Confirmation dialog box is displayed. Click OK. The configured HA pair can be viewed in the list.
Note
- In the Manager, if at least two Sensors are not using same model and software version, an Error dialog box is displayed.
- An option to edit the existing HA pair is not provided. If you double-click a row in the grid, an Error dialog box is displayed. You change the configuration by deleting and re-creating a HA pair.
Most configuration options are done at the HA pair node level. For example, you can now apply a policy or update the configuration at the HA pair node level and it automatically propagates to each of the member Sensors. On the other hand, you still configure the port settings, view interface statistics, and upgrade the Sensor software at the Sensor node level. The easiest way to get a feel for the HA pair configuration process is to examine the user interface once the pair has been created.Note
The Sensors must be running the same software version to run in a failover configuration. However, you upgrade software at a Sensor level, even those that are part of a HA pair. The recommended upgrade procedure is to therefore upgrade the software version on both Sensors, and then restart them sequentially. That is, once the upgrade process is complete on both, restart (for example) the secondary, confirm that it has restarted without error, and then restart the primary.