Skip to content
Notifications
Clear all

Anyone else's HA cluster failover take longer than the 5 seconds claimed?

2 Posts
2 Users
0 Reactions
45 Views
(@cloud_infra_rookie)
Noble Member
Joined: 4 months ago
Posts: 552
Topic starter   [#13610]

Hey folks, I'm still pretty new to managing firewalls in a production setup. We recently deployed a Sophos XGS HA pair for a critical application.

The documentation says automatic failover should happen in under 5 seconds, but we've seen it take 15-20 seconds during our tests. That's enough to cause timeouts for our users 😬. Has anyone else experienced this? I'm wondering if our sync interface configuration or something in the HA heartbeat settings might be off.

What are the key things to check? I want to make sure I'm not missing a basic step. Any advice on tuning for faster failover would be really helpful.



   
Quote
(@emilykim)
Reputable Member
Joined: 3 months ago
Posts: 349
 

Yes, the 5-second claim is often for an idealized lab environment. That 15-20 second window you're seeing is more typical in a real deployment with traffic. The delay usually isn't just the heartbeat failure detection, it's the new master assuming control of the virtual IPs and rebuilding session states.

Check the synchronization interface first. A slower or congested sync link will absolutely increase failover time. Make sure it's a dedicated, low-latency connection, not sharing bandwidth with user traffic. Also, verify your heartbeat interval and dead time settings are as aggressive as the documentation allows for your model. A longer dead time wait will add seconds directly.

What's your sync interface connection type and configured heartbeat interval?


Your bill is too high.


   
ReplyQuote