Combinations of LiSSŪ systems and one or more NITRO switches offer extremely scalable highly available VPN gateway and firewall solutions.
Performance, availability and fault tolerance can be extended easily to any degree by attaching additional LiSSŪ systems and a second NITRO switch.
This high-availability solution ensures that in any combination of single failures all remaining components and connections can still be used. This specifically includes VPN functionality.
NITRO switch intelligently distributes VPN tunnels across an arbitrary amount of identically configured LiSSŪ appliances and permanently monitors all VPN gateways. In case of a hardware failure, established VPN tunnels are transparently diverted from the defective device to another gateway.
-> data sheet
- NITRO switch provides connections to the different zones and distributes the load across the LiSS appliances
- Permanent monitoring of all applications
- Load balancing in case of application or system failure
- Performance and availability are arbritrarily scalable
- NITRO switch makes up Single Point Of Failure
- Components / connections are laid out redundantly
- Bonding of LiSS systems interfaces (conforming to Ethernet 802.3ad)
- NITRO switch with redundant cross-links
- Both NITRO switches are actively engaged in the data transport. If attached devices are accessible via just one NITRO switch the cross-links also carry user data. If one NITRO switch drops out, the other one will recognize the failure. The remaining NITRO switch has all necessary information to take over even already established connections without data loss.
- This example demonstrates several branch offices connected to the high-availability gateway in the central office. All LiSS systems devices at the central office are configured identically and can accept any VPN tunnel. The NITRO switches distribute the tunnels intelligently across the LiSS systems devices while permanently monitoring them. It also exchanges information concerning the establishment, termination and current status of the VPN tunnels with the LiSS appliances. In any failure scenario the entire solution remains operational.
- If a physical connection to a system fails, a backup connection can be established via the second NITRO switch at any time.
- If a LiSS VPN gateway fails, the NITRO switch diverts the existing VPN tunnels to the remaining components.
- If a NITRO switch fails, the second NITRO switch takes over its tasks.