Friday, November 10, 2017

Sonicwall Stateful High Availability and Mismatched Firmware

I've been tasked with resolving a Stateful High Availability setup for 2 Sonicwall NSA 2600's in a very large network that have been left in a bad state.

From what I've gathered, the firmware of the Primary sonicwall was upgraded 113 days ago by a previous admin, and during the process, HA failed over to the Secondary Sonicwall. Firmware was never upgraded on the Secondary appliance, and it has remained the Active device ever since.

My question is regarding best practices for matching the firmware versions back up and restoring Stateful HA, with the Primary sonicwall returning to active status. I need to do so without losing any configuration changes made during these 113 days.

Sonicwall NSA 2600 x2 Primary Firmware Version: 6.2.2.1 (6.2.2.1-14n--HF159825-2n) Secondary Firmware Version: 6.1.2.3 (6.1.2.3-20n)

HA Mode: Active/Standby Secondary has been Active, Primary in Standby for 113 days Found Peer: Yes Settings Synchronized: Yes Stateful HA Synchronized: No

My plan is to utilize the "Synchronize firmware" feature within HA settings on the Secondary appliance to match firmware versions and restore Stateful HA sync, then go through the documented best practices to start the firmware upgrade process from the beginning and get them both to the most recent stable SonicOS.

Will this result in loss of any configuration settings? Any further advice for this process? Thank you in advance!



No comments:

Post a Comment