Re: IPSO Clustering and HA/LS I think before you deploy anything, you should have a better understanding of what your options are, and what the pros/cons of each of them are. Since you have Nokia boxes, your options are only VRRP or IP Clustering. Nothing else. VRRP is HA only. Don't worry about the VRRPv2, MC thing. Just click simplified mode VRRP. It's all monitored circuits now. Very simple, works very well. No special config required anywhere. Failover time is ~3s. IP Clustering is load sharing only. This means you can (in theory) process more traffic than just one node. If you've got two nodes, you're looking at a 10% improvement in connection setup rate, and a 30% improvement in throughput. VPN throughput goes up by more. Clustering can be problematic though, particularly with multicast mode. Some devices (Cisco I'm looking at you) don't like the multicast MAC address, and require manual configuration. You can use forwarding mode instead, but that's not so elegant. Remember also that your cluster has to be able to handle the traffic with a node down. The main advantage you get with clustering, if you're not pushing large amounts of VPN traffic, or in a 3/4 node cluster, is that you get 0.5s failover. So is that worth it to you? Are you at the limits of what the 350/380 can do? Do you even know what those limits are? Or are you just looking to deploy clustering because it's "cool", and VRRP is "passe". Ask yourself what you are trying to achieve. Do you need load sharing, or HA? Do you need fast failover? What is it worth to you? Hide NAT will work fine with both. You should probably have a read of the IPSO Clustering Config guide, from Nokia. |