06-18-2009 01:15 PM
We have 2 SSG520 devices (SSG1 and SSG2) running 5.4r7.0 and they were in HA (Active/Passive). We moved to a new datacenter and took the Passive device (SSG2) to the new datacenter, reconfigured it as a Master and migrated all VPN tunnels to this device. We brought the old master (SSG1) to the new datacenter, reconfigured it as a Backup and need to confirm they are back in sync.
I called Juniper and they said they are in sync, but I am seeing differences in the routes. Please assist. Once in sync, the backup (SSG1) needs to be imported into NSM and added to the current Cluster.
06-18-2009 04:31 PM
06-19-2009 08:57 AM
if they are eBGP routes then its correct. We only support dynamic route syn from 6.0r2 onwards and you are running 5.4 right now, so it means that the dynamic routes will not be synced over to the backup.