Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Group and Ungroup MNHA Devices

Multinode High Availability (MNHA) is a solution for SRX Series Firewalls that enables multiple devices to operate together with active control and data planes, ensuring resilient service continuity across locations. Juniper Security Director enables the grouping of two standalone devices to form an MNHA pair and supports ungrouping existing MNHA pairs back into standalone devices.

Group two standalone devices configured as an MNHA pair using CLI on devices outside Juniper Security Director or through templates and ungroup existing MNHA pairs back to standalone devices.

When you group two devices, Juniper Security Director pairs them as an MNHA cluster, ensures MNHA state is updated correctly, and continues to collect and display monitoring data for the pair. When an MNHA device is unpaired, each device reverts to standalone mode, with configuration and other device operations continuing to work as expected. Grouping or ungrouping devices do not modify their configurations.

Group MNHA Devices

Before You Begin:
  • Verify the selected devices are standalone and configure them as MNHA using CLI.
  • If the standalone devices aren't configured as MNHA using the CLI, use one or both of the following configuration templates based on your requirements:

    • MNHA-STATELESS-ACTIVE-ACTIVE-ROUTING—Configure MNHA with services redundancy group (SRG) 0 in active-active stateless routing mode.

    • MNHA-ACTIVE-BACKUP-ALL-MODES—Configure MNHA with SRG 1 in active-backup mode for all deployment types (routing, switching, or hybrid) with the managed IPsec services.

    Reboot the device after you deploy the configuration for the changes to take effect.

    For more information about configuration templates, see Configuration Templates Overview and Add and Manage Configuration Templates.

  • Make sure the MNHA devices are onboarded and connected to Juniper Security Director.
  • Ensure that both the devices are the same SRX Series Firewall model and run the same Junos release.
  1. Click Inventory > Devices and select the two devices to group.
  2. Click More and select Group MNHA Devices from the drop-down menu.
  3. Click Yes to confirm.

    A grouping job with a job ID is created and displayed. You can track the job progress on the Admin > Jobs page. Grouped devices are displayed as an MNHA pair on the Devices page.

    The Management Status column displays the following statuses during the process:

    Table 1: Statuses in the Management Column
    Status Description

    Grouping in progress

    MNHA grouping is in progress

    Incorrect configuration

    Device configurations do not match.

    Ungroup MNHA Devices link is provided.

    MNHA discovery failed

    Device synchronization failed.

    Ungroup MNHA Devices link is provided.

Ungroup MNHA Pairs

Before You Begin:

Ensure that there are no pending jobs on the MNHA paired devices and the devices do not display the following statuses:

  • Discovery Not Initiated
  • Grouping in Progress
  • Ungrouping in Progress
  1. Click Inventory > Devices and select the required MNHA pair.
  2. Click More and select Ungroup an MNHA pair.
    You can ungroup only one MNHA pair at a time.
  3. Click Yes to confirm.

    A message with ungrouping in progress is displayed.

    You can use the SRX Series Firewall devices as standalone devices after the ungrouping process completes.