Version 7.2 813 Mediant 800B Gateway & E-SBC
User's Manual 42. HA Configuration
device (through the Maintenance interface).
HA-related configuration on the active device is automatically updated on the
redundant device:
• Maintenance interface:
♦ Modified Maintenance interface address of the active device: The address is
set as the new 'HA Remote Address' value on the redundant device.
♦ Modified 'HA Remote Address' value on the active device: The address is
set as the new Maintenance interface address on the redundant device
(requires a device reset).
♦ Modifications on all other Maintenance interface parameters (e.g., Default
Gateway and VLAN ID): updated to the Maintenance interface on the
redundant device.
• 'Preempt Mode' parameter (requires a device reset).
• 'Preempt Priority' parameter is set for the active device.
• Modified 'Redundant Preempt Priority' value is set for the redundant device
(requires a device reset).
Note: If the HA system is already in HA Preempt mode and you want to change the
priority of the device, to ensure that system service is maintained and traffic is not
disrupted, it is recommended to set the higher priority to the redundant device and
then reset it. After it synchronizes with the active device, it initiates a switchover and
becomes the new active device (the former active device resets and becomes the
new redundant device).
42.3 Configuring Firewall Allowed Rules
If you want to configure firewall rules (see 'Configuring Firewall Rules' on page 175) that
block specific network traffic, you must first configure firewall rules that allow traffic
needed in your deployment. Therefore, in addition to allowing basic traffic (such as OAMP,
SIP signalling, and media), you must also allow HA maintenance traffic between the Active
and Redundant devices:
UDP ports 669, 670 and 680 (HA synchronization and keep alive)
TCP ports 2442 and 80 (HA control and data)
Please configure firewall rules 10 through 21, as shown below, where 10.31.4.61 is the IP
address of the Maintenance interface ("HA_IF") of the Redundant device and 10.31.4.62
the IP address of the Maintenance interface ("HA_IF") of the Active device.
Allowed Firewall Rules for HA
Index Source IP
Port
Prefix
Length
Start
Port
End Port
Protocol
Use
Specific
Interface
Interface
Name
Action
Upon
Match
Packet
Size
Byte
Rate
Byte
Burst
0
Various rules for basic traffic.
...
9
10
10.31.4.61 669 32 669 669 udp Enable HA_IF Allow 0 0 0
11
10.31.4.62 669 32 669 669 udp Enable HA_IF Allow 0 0 0