SunScreen 3.1 Administration Guide

HA Policy

When you set up an HA cluster, you designate one Screen as the Primary HA Screen, and you configure it with the common objects and policy rules the HA cluster will use. When you activate the policy, it is copied from the Primary HA Screen to the other members of the HA cluster. The Solaris system and network configuration are not copied from the Primary HA Screen, and must be identical on all the Screens in the HA cluster.


Note -

Keep the HA network physically secure because the HA cluster transmits secret keys and policies in the clear over the dedicated HA network.


The interfaces for network connections must be the same for each HA cluster member. For example, if one HA host uses the le0 interface as its dedicated internal network connection, all HA hosts must use the le0 network interface as the dedicated internal network connection. Similarly, you must assign Screens in the HA cluster the same IP addresses on their non-dedicated interfaces.