# HA active-active

**URL:** <https://community.a10networks.com/t/ha-active-active/135>\
**Category:** System\
**Created:** [January 19, 2012, 6:25am UTC](https://community.a10networks.com/t/ha-active-active/135 "2012-01-19T06:25:01Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbanares](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@dbanares](https://community.a10networks.com/u/dbanares)\
**Post date:** [January 19, 2012, 6:25am UTC](https://community.a10networks.com/t/ha-active-active/135/1 "2012-01-19T06:25:01Z")

</div>

Hi,

I have two AX3000, I want to have an HA active-active deployment. Is this possible in Large Scale NAT implementation? If that so, can you give me some example configuration.

Thanks,

Dannel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [January 20, 2012, 9:13pm UTC](https://community.a10networks.com/t/ha-active-active/135/2 "2012-01-20T21:13:25Z")

</div>

Hi Dannel,

That’s indeed also possible with LSN implementation. And the configuration is the very same as what you did on your SLB active-active deployment. You simply configure: . HA with preempt . 2 HA groups with different priorities =\> AX1 is active on 1 group and standby on the other group . 2 HA Floating VIP =\> each device receives the traffic it’s supposed to receive

I attached a config sample as example. Dimitri

---

<div class="post-metadata">

**Author:** ![dbanares](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@dbanares](https://community.a10networks.com/u/dbanares)\
**Post date:** [January 24, 2012, 6:16am UTC](https://community.a10networks.com/t/ha-active-active/135/3 "2012-01-24T06:16:48Z")

</div>

Hi,

Do I need also a VIP for my outside interface?

Thanks,

---

<div class="post-metadata">

**Author:** ![dshin](https://avatars.discourse-cdn.com/v4/letter/d/f05b48/32.png) [@dshin](https://community.a10networks.com/u/dshin)\
**Post date:** [January 24, 2012, 6:22pm UTC](https://community.a10networks.com/t/ha-active-active/135/4 "2012-01-24T18:22:17Z")

</div>

Hi Dannel,

Can you please elaborate your question? LSN will not allow VIP in the configuration. The way LSN works is by selecting an IP address from the NAT pool and using it as a source for the session(outbound connection).

Regards,

Genard

---

<div class="post-metadata">

**Author:** ![dbanares](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@dbanares](https://community.a10networks.com/u/dbanares)\
**Post date:** [January 25, 2012, 2:08am UTC](https://community.a10networks.com/t/ha-active-active/135/5 "2012-01-25T02:08:07Z")

</div>

Hi,

What I mean is, floating IP for my outside interface. Like I said, I have two AX3000 and I want to have active-active deployment. One AX is deployed to my main site and one AX is deployed to other site, and I have a dedicated link to connect each AX for the HA interface.

I have attached a sample topology.

Thanks,

Dannel

---

<div class="post-metadata">

**Author:** ![dbanares](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@dbanares](https://community.a10networks.com/u/dbanares)\
**Post date:** [January 25, 2012, 2:12am UTC](https://community.a10networks.com/t/ha-active-active/135/6 "2012-01-25T02:12:51Z")

</div>

Sorry, here’s the attachment.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [January 25, 2012, 5:19am UTC](https://community.a10networks.com/t/ha-active-active/135/7 "2012-01-25T05:19:16Z")

</div>

Looking at your diagram, it does not seem like the two boxes can be in HA. If box 1 touches the outside and box 2 only touch in the inside, they are really more like 2 stand alone boxes. You have single points of failure. Maybe I just don’t understand your diagram.

---

<div class="post-metadata">

**Author:** ![dtidwell](https://avatars.discourse-cdn.com/v4/letter/d/6f9a4e/32.png) [@dtidwell](https://community.a10networks.com/u/dtidwell)\
**Post date:** [January 25, 2012, 7:32pm UTC](https://community.a10networks.com/t/ha-active-active/135/8 "2012-01-25T19:32:55Z")

</div>

Agreed, I can’t see how HA is achieved with the sample topology. Also, it’s unclear what sorts of failures you are trying to protect against.

For the floating IP to work effectively, the AX devices need to share the same L2 domain that you want the floating IP to be on. From the diagram, it looks like the core switches need to be connected. This would allow trunking of both the internal and external VLANs the AX’s are connecting to.

---

<div class="post-metadata">

**Author:** ![dbanares](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@dbanares](https://community.a10networks.com/u/dbanares)\
**Post date:** [January 26, 2012, 1:00am UTC](https://community.a10networks.com/t/ha-active-active/135/9 "2012-01-26T01:00:07Z")

</div>

Yes, you are right dtidwell. I just forgot to put a link in two core switch in my diagram, but they are in L2 mode. All the vlans from Main office are extended to the branch office, and vice versa.

Now I’m getting the idea.

Thanks,

Dannel
