ON THIS PAGE
Group and Ungroup MNHA Devices
Multinode High Availability (MNHA) is a solution for SRX Series Firewalls that enables multiple devices to operate together with active control and data planes, ensuring resilient service continuity across locations. Juniper Security Director enables the grouping of two standalone devices to form an MNHA pair and supports ungrouping existing MNHA pairs back into standalone devices.
Group two standalone devices configured as an MNHA pair using CLI on devices outside Juniper Security Director or through templates and ungroup existing MNHA pairs back to standalone devices.
When you group two devices, Juniper Security Director pairs them as an MNHA cluster, ensures MNHA state is updated correctly, and continues to collect and display monitoring data for the pair. When an MNHA device is unpaired, each device reverts to standalone mode, with configuration and other device operations continuing to work as expected. Grouping or ungrouping devices do not modify their configurations.
Group MNHA Devices
- Verify the selected devices are standalone and configure them as MNHA using CLI.
-
If the standalone devices aren't configured as MNHA using the CLI, use one or both of the following configuration templates based on your requirements:
-
MNHA-STATELESS-ACTIVE-ACTIVE-ROUTING—Configure MNHA with services redundancy group (SRG) 0 in active-active stateless routing mode.
-
MNHA-ACTIVE-BACKUP-ALL-MODES—Configure MNHA with SRG 1 in active-backup mode for all deployment types (routing, switching, or hybrid) with the managed IPsec services.
Reboot the device after you deploy the configuration for the changes to take effect.
For more information about configuration templates, see Configuration Templates Overview and Add and Manage Configuration Templates.
-
- Make sure the MNHA devices are onboarded and connected to Juniper Security Director.
- Ensure that both the devices are the same SRX Series Firewall model and run the same Junos release.
Ungroup MNHA Pairs
Ensure that there are no pending jobs on the MNHA paired devices and the devices do not display the following statuses:
- Discovery Not Initiated
- Grouping in Progress
- Ungrouping in Progress