Prerequisites for clustering
Review these prerequisites before configuring clustering on Secure Firewall devices.
Model requirements
-
Secure Firewall 3100—Maximum 16 nodes
-
Secure Firewall 4200—Maximum 16 nodes
-
Secure Firewall 6100—Maximum 4 nodes
User roles
-
Admin
-
Access Admin
-
Network Admin
Hardware and software requirements
-
All units in a cluster must be the same model.
-
All units must include the same number of interfaces, the same network modules, and the same network module slot assignments.
-
The Cloud-Delivered Firewall Management Center access must be from the Management interface; data interface management is not supported.
-
All units must run the identical software except at the time of an image upgrade. Hitless upgrade is supported.
-
All units must be in the same firewall mode, routed or transparent.
-
All units must use the same compliance mode.
-
If core allocation is supported, all units must use the same core allocation profile.
-
All units must be in the same domain and the same group, with no deployment pending or in progress.
-
The control node must not have any unsupported features configured (refer Unsupported features with clustering), and data nodes must not have any VPN configured. The control node can have site-to-site VPN configured.
Switch requirements
Be sure to complete the switch configuration before you configure clustering. Make sure the ports connected to the cluster control link have the correct (higher) MTU configured. By default, the cluster control link MTU is set to 100 bytes higher than the data interfaces. If the switches have an MTU mismatch, the cluster formation will fail.