feature | Device HA | Device HA Pro |
License | None required. | Need a license. |
Role | Role of Master and Backup is configurable. Master takes over from Backup if the Master goes down and then becomes the Master again if it comes back online again (failback). | Role of active and passive is not configurable. The active model is the one whose heartbeat interface comes online first. The passive becomes active if active goes down and stays active even if the previous active comes online again. |
Firmware Upgrade | Master remains Master by default when new firmware is uploaded. | If Device HA Pro is enabled, then both the active and passive Zyxel Device must be online and connected in order to upload firmware. New firmware is first uploaded to the passive device and then uploaded to the active device. By default, the passive device reboots after firmware upload making it become the active device. Don’t select the Reboot prompt after uploading firmware to the passive device if you want the passive device to remain passive when new firmware is uploaded. Alternatively, disable Device HA Pro if you want to just upload firmware to the active Zyxel Device. |
What is synchronized | Configuration file | Configuration file, device time, IPv4/v6 TCP sessions, IPSec VPN tunnels, user login/logout information, AV/IDP signatures, DHCP table, IP/MAC binding table. |
Maximum Failover Count | 0 | 5 (default) to 50. Can be reset by command. |
Best case Failover delay | 10~30 seconds to rebuild connections. | 0~1 seconds. |
Monitored Interfaces | Ethernet | Ethernet, VLAN, Bridge, LAG |
Dedicated monitor port | No | Heartbeat interface. Remove Ethernet, VLAN, Bridge, LAG configurations from this port first. |
Label | Description |
Enable Device HA | Select this to turn the Zyxel Device’s Device HA feature on. With Device HA, it is not recommended to use STP (Spanning Tree Protocol) on a switch connected to the Zyxel Device. |
Device HA Mode | This displays whether the Zyxel Device is currently set to use Device HA or Device HA Pro. You need a license to use Device HA Pro. Click the link to go to the screen where you can configure the Zyxel Device to use Device HA pro if it is not currently using it and you have a license. |
Monitored Interface Summary | This table shows the status of the interfaces that you selected for monitoring in the other Device HA screens. |
# | This is the entry’s index number in the list. |
Interface | These are the names of the interfaces that are monitored by Device HA. |
Virtual Router IP / Netmask | This is the interface’s IP address and subnet mask. Whichever Zyxel Device is the master uses this virtual router IP address and subnet mask. |
Management IP / Netmask | This field displays the interface’s management IP address and subnet mask. You can use this IP address and subnet mask to access the Zyxel Device whether it is in master or backup mode. |
Link Status | This tells whether the monitored interface’s connection is down or up. |
HA Status | The text before the slash shows whether the device is configured as the master or the backup role. This text after the slash displays the monitored interface’s status in the virtual router. Active - This interface is up and using the virtual IP address and subnet mask. Stand-By - This interface is a backup interface in the virtual router. It is not using the virtual IP address and subnet mask. Fault - This interface is not functioning in the virtual router right now. In Device HA if one of the master Zyxel Device’s interfaces loses its connection, the master Zyxel Device forces all of its interfaces to the fault state so the backup Zyxel Device can take over all of the master Zyxel Device’s functions. |
Device HA Pro Service | |
Service Status | This shows if Device HA Pro is licensed on the Zyxel Device. If not, click Buy to purchase a license and then click Register Now to activate it at myZyxel. These are the steps to activate a Device HA Pro license on your active and passive Zyxel Devices. 1. Buy a Device HA Pro iCard. The card contains two keys. 2. Register your active and passive Zyxel Devices at myZyxel. 3. Activate the license by entering one key on the active Zyxel Device and the other key on the passive Zyxel Device. It doesn’t matter which Zyxel Device is actually active or passive as this is dynamic in Device HA Pro. |
Register Now | Click the link to go to myZyxel where you can register your Zyxel Device and activate the service. This link is available only when the service is not activated yet. |
Apply | Click Apply to save your changes back to the Zyxel Device. |
Reset | Click Reset to return the screen to its last-saved settings. |
Label | Description |
Show Advanced Settings / Hide Advanced Settings | Click this button to display a greater or lesser number of configuration fields. |
Device Role | Select the Device HA role that the Zyxel Device plays in the virtual router. Choices are: Master - This Zyxel Device is the master Zyxel Device in the virtual router. This Zyxel Device uses the virtual IP address for each monitored interface. Do not set this field to Master for two or more Zyxel Devices in the same virtual router (same cluster ID). Backup - This Zyxel Device is a backup Zyxel Device in the virtual router. This Zyxel Device does not use any of the virtual IP addresses. |
Priority | This field is available for a backup Zyxel Device. Type the priority of the backup Zyxel Device. The backup Zyxel Device with the highest value takes over the role of the master Zyxel Device if the master Zyxel Device becomes unavailable. The priority must be between 1 and 254. (The master interface has priority 255.) |
Enable Preemption | This field is available for a backup Zyxel Device. Select this if this Zyxel Device should become the master Zyxel Device if a lower-priority Zyxel Device is the master when this one is enabled. (If the role is master, the Zyxel Device preempts by default.) |
Cluster Settings | |
Cluster ID | Type the cluster ID number. A virtual router consists of a master Zyxel Device and all of its backup Zyxel Devices. If you have multiple Zyxel Device virtual routers on your network, use a different cluster ID for each virtual router. |
Authentication | Select the authentication method the virtual router uses. Every interface in a virtual router must use the same authentication method and password. Choices are: None - this virtual router does not use any authentication method. Text - this virtual router uses a plain text password for authentication. Type the password in the field next to the radio button. The password can consist of alphanumeric characters, the underscore, and some punctuation marks (+-/*= :; .! @$&%#~ ‘ \ () ), and it can be up to eight characters long. IP AH (MD5) - this virtual router uses an encrypted MD5 password for authentication. Type the password in the field next to the radio button. The password can consist of alphanumeric characters, the underscore, and some punctuation marks (+-/*= :; .! @$&%#~ ‘ \ () ), and it can be up to eight characters long. |
Monitored Interface Summary | This table shows the status of the Device HA settings and status of the Zyxel Device’s interfaces. |
Edit | Select an entry and click this to be able to modify it. |
Activate | To turn on an entry, select it and click Activate. |
Inactivate | To turn off an entry, select it and click Inactivate. |
# | This is the entry’s index number in the list. |
Status | The activate (light bulb) icon is lit when the entry is active and dimmed when the entry is inactive. |
Interface | This field identifies the interface. At the time of writing, Ethernet and bridge interfaces can be included in the Device HA virtual router. The member interfaces of any bridge interfaces do not display separately. |
Virtual Router IP / Netmask | This is the master Zyxel Device’s (static) IP address and subnet mask for this interface. If a backup takes over for the master, it uses this IP address. These fields are blank if the interface is a DHCP client or has no IP settings. |
Management IP / Netmask | This field displays the interface’s management IP address and subnet mask. You can use this IP address and subnet mask to access the Zyxel Device whether it is in master or backup mode. |
Link Status | This tells whether the monitored interface’s connection is down or up. |
Synchronization | Use synchronization to have a backup Zyxel Device copy the master Zyxel Device’s configuration, certificates, AV signatures, IDP and application patrol signatures, and system protect signatures. Every interface’s management IP address must be in the same subnet as the interface’s IP address (the virtual router IP address). |
Server Address | If this Zyxel Device is set to backup role, enter the IP address or Fully-Qualified Domain Name (FQDN) of the Zyxel Device from which to get updated configuration. Usually, you should enter the IP address or FQDN of a virtual router on a secure network. If this Zyxel Device is set to master role, this field displays the Zyxel Device’s IP addresses and/or Fully-Qualified Domain Names (FQDN) through which Zyxel Devices in backup role can get updated configuration from this Zyxel Device. |
Sync. Now | This displays if the Zyxel Device is set to use Device HA, the Zyxel Device is in the backup role and Device HA is enabled. Click this to copy the specified Zyxel Device’s configuration. |
Server Port | If this Zyxel Device is set to the backup role, enter the port number to use for Secure FTP when synchronizing with the specified master Zyxel Device. If this Zyxel Device is set to master role, this field displays the Zyxel Device’s Secure FTP port number. Click the Configure link if you need to change the FTP port number. Every Zyxel Device in the virtual router must use the same port number. If the master Zyxel Device changes, you have to manually change this port number in the backups. |
Password | Enter the password used for verification during synchronization. Every Zyxel Device in the virtual router must use the same password. If you leave this field blank in the master Zyxel Device, no backup Zyxel Devices can synchronize from it. If you leave this field blank in a backup Zyxel Device, it cannot synchronize from the master Zyxel Device. |
Retype to Confirm | Type the password again here to confirm it. |
Auto Synchronize | You see the following fields when the Zyxel Device is a Backup. Select this to get the updated configuration automatically from the specified Zyxel Device according to the specified Interval. The first synchronization begins after the specified Interval; the Zyxel Device does not synchronize immediately. |
Interval | When you select Auto Synchronize, set how often the Zyxel Device synchronizes with the master. |
Next Sync Time | This appears the next time and date (in hh:mm yyyy-mm-dd format) the Zyxel Device will synchronize with the master. |
Apply | This appears when the Zyxel Device is currently using Device HA. Click Apply to save your changes back to the Zyxel Device. |
Reset | Click Reset to return the screen to its last-saved settings. |
Label | Description |
Enable Monitored Interface | Select this to have Device HA monitor the status of this interface’s connection. |
Interface Name | This identifies the interface. Do not connect the bridge interfaces on two Zyxel Devices without Device HA activated on both. Doing so could cause a broadcast storm. Either activate Device HA before connecting the bridge interfaces or disable the bridge interfaces, connect the bridge interfaces, activate Device HA, and finally reactivate the bridge interfaces. |
Virtual Router IP (VRIP) / Subnet Mask | This is the interface’s (static) IP address and subnet mask in the virtual router. Whichever Zyxel Device is currently serving as the master uses this virtual router IP address and subnet mask. These fields are blank if the interface is a DHCP client or has no IP settings. |
Manage IP | Enter the interface’s IP address for management access. You can use this IP address to access the Zyxel Device whether it is the master or a backup. This management IP address should be in the same subnet as the interface IP address. |
Manage IP Subnet Mask | Enter the subnet mask of the interface’s management IP address. |
OK | Click OK to save your changes back to the Zyxel Device. |
Cancel | Click Cancel to exit this screen without saving your changes. |
Label | Description |
Active Device Status | This section displays information on the active Zyxel Device with an activated Device HA Pro license. |
Health Status | This displays Off or On depending on whether Device HA Pro is disabled or enabled on the active Zyxel Device. |
S/N | This displays the serial number of the active Zyxel Device. |
MAC | This displays the hardware MAC address of the active Zyxel Device with an activated Device HA Pro license. |
Synch Status | This displays the synchronization progress, No Progress / Fail / Abort / Success / In Progress, between the active Zyxel Device with an activated Device HA Pro license and the passive Zyxel Device. |
Passive Device Status | This section displays information on the passive Zyxel Device with an activated Device HA Pro license. |
Health Status | This displays Off or On depending on whether Device HA Pro is disabled or enabled on the passive Zyxel Device. |
S/N | This displays the serial number of the passive Zyxel Device. |
MAC | This displays the hardware MAC address of the passive Zyxel Device. |
Synch Status | This displays the synchronization progress, No Progress / Fail / Abort / Success / In Progress, between the passive Zyxel Device with an activated Device HA Pro license and the active Zyxel Device. |
Device HA Pro Service | These are the steps to activate a Device HA Pro license on your active and passive Zyxel Devices. 1. See your Device HA Pro iCard. The card contains two keys. 2. Register your active and passive Zyxel Devices at myZyxel. 3. Activate the license by entering one key on the active Zyxel Device and the other key on the passive Zyxel Device. It doesn’t matter which Zyxel Device is actually active or passive as this is dynamic in Device HA Pro. |
Service Status | This field displays whether a service license is enabled at myZyxel (Activated) or not (Not Activated) or expired (Expired). It displays the remaining Grace Period if your license has Expired. It displays Not Licensed if there isn’t a license to be activated for this service. If you need a license or a trial license has expired, click Buy to buy a new one. If a Standard license has expired, click Renew to extend the license. Then, click Activate to connect with the myZyxel server to activate the new license. |
Apply | Click Apply to save your changes back to the Zyxel Device. |
Reset | Click Reset to return the screen to its last-saved settings. |
Label | Description |
Enable Device HA | Select this to turn the Zyxel Device’s Device HA Pro feature on. |
Enable Configuration Provisioning From Active Device. | Select this to have a passive Zyxel Device copy the active Zyxel Device’s configuration, signatures (anti-virus, IDP/application patrol, and system protect), and certificates. Only Zyxel Devices of the same model and firmware version can synchronize. |
Serial Number of Licensed Device for License Synchronization | Type the serial number of the Zyxel Device (active or passive) with the Device HA Pro subscribed license. |
Active Device Management IP | Type the IPv4 address of the highest-numbered port on the active Zyxel Device (the heartbeat dedicated link port). |
Passive Device Management IP | Type the IPv4 address of the highest-numbered port on the passive Zyxel Device (the heartbeat dedicated link port). The active and passive Zyxel Device Management IP addresses must be in the same subnet. |
Subnet Mask | Type the subnet mask for the management IP addresses. |
Password | Type a synchronization password of between 1 and 32 single-byte printable characters. You will be prompted for the password before synchronization takes place. |
Retype to Confirm | Type the exact same synchronization password as typed above. |
Heartbeat Interval | Type the number of seconds (1-10) allowed for absence of a heartbeat signal before a failure of the active Zyxel Device is recorded. |
Heartbeat Lost Tolerance | Type the number of heartbeat failures allowed before failover is activated on the passive Zyxel Device. |
Monitor Interface | Select an interface in Available Interfaces and click the right-arrow button to move it to Monitor Interface to become a Device HA pro monitored interface. To remove a Device HA pro monitored interface, select it in Monitor Interface and click the left-arrow button to move it to Available Interfaces. |
Failover Detection | |
Enable Failover When Interface Failure (Option) | Select this to have the passive Zyxel Device take over when a monitored interface fails. |
Enable Failover When Device Service Fails (Option) | Select this to have the passive Zyxel Device take over when a monitored service daemon on the active Zyxel Device fails. |
Apply & switch to Device HA Pro | Click Apply to save your changes back to the Zyxel Device and change the Zyxel Device to begin using Device HA Pro from Device HA (general) if it isn’t already. You need a Device HA Pro license registered at myZyxel to do this. |
Apply | Click Apply to save your Device HA Pro configurations back to the Zyxel Device but keep the Zyxel Device using Device HA (general). |
Reset | Click Reset to return the screen to its last-saved settings. |
Label | Description |
Logs | |
Active Device | This displays Device HA Pro logs on the active Zyxel Device. |
Passive Device | This displays Device HA Pro logs on the passive Zyxel Device. |
Refresh | Click Refresh to update information in this screen. |