SonicWALL 3500 User Manual

Page of 74
Page 28
  Configuring a State Sync Pair in NAT/Route Mode  
Configuring a State Sync Pair in 
NAT/Route Mode
This section provides instructions for configuring a pair of 
SonicWALL NSA appliances for high availability (HA). This 
section is relevant to administrators following deployment 
scenario B.
This section contains the following sub-sections:
Initial High Availability Setup
Before you begin the configuration of HA on the Primary 
SonicWALL security appliance, perform the following setup:
1.
On the bottom panel of the Backup SonicWALL security 
appliance, locate the serial number and write the number 
down. You need to enter this number in the High 
Availability > Settings page.
2.
Verify that the Primary SonicWALL and Backup 
SonicWALL security appliances are registered, running the 
same SonicOS Enhanced versions, and running the same 
SonicWALL Security services.
3.
Make sure the Primary SonicWALL and Backup 
SonicWALL security appliances’ LAN, WAN and other 
interfaces are properly configured for failover.
4.
Connect the X5 ports on the Primary SonicWALL and 
Backup SonicWALL appliances with a CAT6-rated 
crossover cable (red crossover cable). The Primary and 
Backup SonicWALL security appliances must have a 
dedicated connection. SonicWALL recommends cross-
connecting the two together using a CAT6 crossover 
Ethernet cable, but a connection using a dedicated hub/
switch is also valid.
5.
Power up the Primary SonicWALL security appliance, and 
then power up the Backup SonicWALL security appliance.
6.
Do not make any configuration changes to the Primary’s 
HA interface; the High Availability configuration in an 
upcoming step takes care of this issue. When done, 
disconnect the workstation.
SonicWALL NSA 1
SonicWALL NSA 2
Network Security Appliance
Network Security Appliance
NSA
Local Network 
SonicWALL
HA / Failover Pair 
Internet
X5 HA Link