Hi All,
I am new to Mikrotik and I have 2 RB3011UiAS-RM firewalls, one configured and working properly and another which is still boxed.
I want to set up the two firewall in HA and to ensure redundancy.
Is there a step by step guide that i may use to follow to achieve the setup.
Please bear in mind that I am very new to Mikrotik.... and don't have that knowledge...
any help is appreciated.
I found this article but would that copy the config from the master to primary to the backup?
https://wiki.mikrotik.com/wiki/Manual:VRRP-examples
There's no true HA feature in RouterOS.
That means that no state is synced/shared between two routerboards.
Also no configuration can be automatically synced/copied between two routerboards without custom scripting.
This means that if you do connection tracking (which I am certain you do) in your firewall when doing failover to the adjacent router, the connection tracking table is not synced. So established/related connections, NAT, etc will break for a few seconds and connections to end users will drop.
This feature has been requested since 2014
viewtopic.php?f=19&t=83697&hilit=conntrackd
For web browsing this might not be a big issue, but for realtime stuff (eg: VoIP) it's really problematic.
If you do pure routing without NAT or generally stateful firewall, failover can work just fine right away.
Also you will have to manually sync any configuration changes on both routers. Either manually (which can get bad really quick) or via custom scripting or external scripting/programming (which can become restricting in what you can do withing RouterOS).
If you are fluent in networking in general, you shouldn't have any issues implementing what you need on MikroTik. MikroTik makes it rather easy to implement stuff when you understand at least the basics of TCP/IP, packet flows, etc. I've always found their UIs very intuitive even for stuff that I wasn't originally familiar with.
If not, you are in for a steep learning curve when tackling advanced stuff like HA.