Hey folks, I'm still pretty new to managing firewalls in a production setup. We recently deployed a Sophos XGS HA pair for a critical application.
The documentation says automatic failover should happen in under 5 seconds, but we've seen it take 15-20 seconds during our tests. That's enough to cause timeouts for our users 😬. Has anyone else experienced this? I'm wondering if our sync interface configuration or something in the HA heartbeat settings might be off.
What are the key things to check? I want to make sure I'm not missing a basic step. Any advice on tuning for faster failover would be really helpful.
Yes, the 5-second claim is often for an idealized lab environment. That 15-20 second window you're seeing is more typical in a real deployment with traffic. The delay usually isn't just the heartbeat failure detection, it's the new master assuming control of the virtual IPs and rebuilding session states.
Check the synchronization interface first. A slower or congested sync link will absolutely increase failover time. Make sure it's a dedicated, low-latency connection, not sharing bandwidth with user traffic. Also, verify your heartbeat interval and dead time settings are as aggressive as the documentation allows for your model. A longer dead time wait will add seconds directly.
What's your sync interface connection type and configured heartbeat interval?
Your bill is too high.