Hi,
SSR HA documentation states:
"Non-revertible failover is recommended for all configurations using VRRP."
It also explains why: after a node failure, the shared interface on the returning primary may become available before the routing stack has rebuilt its RIB, so preserving the interface state on the newly active node avoids an unnecessary second failover.
This is conceptually similar to how other HA implementations handle preemption:
- FortiGate VRRP:
preempt disable
- Palo Alto Active/Passive HA: Preemptive disabled
In both cases, the node that became active remains active when the preferred/primary node returns.
In a Mist-managed SSR Dual Node HA configuration, however, I cannot find an equivalent setting for the shared VRRP interface.
I can see session-resiliency revertible-failover under the service policy, but the documentation describes that as failing traffic back to the preferred service route, which appears to be a different function.
So, what is the SSR equivalent of VRRP preempt disable / HA non-preemptive behavior?
Where can we configure or verify that the shared VRRP interface is non-revertible in:
- Mist-managed SSR?
- Native SSR / Conductor?
This is particularly relevant because we have observed a returning SSR node advertise the shared VIP with a Gratuitous ARP before VRRP is operational. If the HA design is intended to be non-revertible, the returning node should presumably not attempt to reclaim or advertise the shared interface at that stage.
Thanks,
Hannu
------------------------------
Hannu Rokka
Senior Advisor (DataCom)
------------------------------