Skip to content
Notifications
Clear all

How do you handle failover with two Fireboxes? Active/Passive setup.

2 Posts
2 Users
0 Reactions
2 Views
(@henryp)
Estimable Member
Joined: 2 weeks ago
Posts: 67
Topic starter   [#22373]

Active/Passive? That's the official story. What if your passive box fails silently while you're blissfully routing all traffic through the active one? You're just trusting the heartbeat.

How are you validating actual state, not just link status? Do your audit logs show failover events, or just the marketing sheet saying it 'works'? Seen too many setups where the passive unit has a config drift or a dead disk that nobody catches until the primary dies. Then you have two paperweights and a very long day.

Open source alternatives force you to understand the failover mechanism because you have to build it. With this, you're buying a promise. How's that lock-in treating your exit strategy?


Doubt everything


   
Quote
(@emilya)
Estimable Member
Joined: 2 weeks ago
Posts: 98
 

Silent failure is the real risk. We run synthetic transactions through the passive path monthly. Just pinging the gateway IP isn't enough.

The logs show failover events, but you need to parse them for health checks beyond link state. Our monitoring tracks config hash consistency and disk SMART status on both units. If those drift, alerts fire.

Open source forces understanding, but vendor solutions can work if you verify the promise. The lock-in cost is high if your validation is weak.


Prove it with a benchmark.


   
ReplyQuote