Distribution of appliance workload upon failover

 

When Appliance/s fail, the workload of the Appliance is distributed using an internal mechanism across the failover cluster/scope such that the recipient Appliance/s can best handle the newly acquired failover assignment. This is done so that the recipient Appliance/s are not overburdened or unable to handle the additional devices. A single IP Range assignment may be distributed across multiple Appliances.

Endpoints and network devices are first distributed to other Appliances that have free capacity within the same failover cluster. When no Appliances in the cluster have free capacity, assignments are distributed to Appliances in other clusters in the failover scope.

Distribution is based on appliances' load of endpoints and switches. See Switch Information and failover clustering for more details.

Note: The new IP assignment of recipient Appliances is not reflected in the Console, in, for example, the Assigned IPs column in the CounterACT Devices pane. You can, however, view which recipient Appliance is handling a specific endpoint. See View Indication of Recipient Appliances Handling Endpoints.

Recalculation of appliance failover assignments

 

In an environment where one or more Appliances fail, the following events trigger a recalculation of the failover assignments, and may cause these assignments to be redistributed:

  • An Appliance reconnects after failure
  • An Appliance is removed from a failover cluster
  • An Appliance is added to a failover cluster
  • A failover scope assignment is changed
  • A failover cluster is enabled/disabled
  • Failover is disabled/enabled for an Appliance

Handling endpoints that exceed capacity

 

Each Appliance has a set number of endpoints allotted to the Appliance. This number is set automatically based on default values assigned to the hardware model of your Appliance. This is the Appliance Capacity. Refer to Appliance Endpoint Performance Capacity.

When a failover occurs, and an Appliance receives a Failover Assignment, the Appliance Capacity may be exceeded. In such a case, any endpoints exceeding the capacity are not fully handled by the Appliance. Such Failover Excess endpoints are displayed in the Console Detections pane, but not all of their host properties are fully resolved. This means that these endpoints will not match policies that depend on such unresolved properties, and as a result, the relevant actions will not be applied to the endpoints.

You can track the number of excess endpoints by viewing the Failover Excess column in the Failover Status table. When configuring failover clusters, verify that you have sufficient capacity to handle all endpoints so that no endpoints exceed capacity if a failure occurs. See View Information about Failover Status for more information. You can also view excess endpoints using a filter in the Detections pane. See Filter Endpoint Failover Information for more information.