Configuring NetScreen Firewalls

By now we have explored most aspects of NSRP, but there are still a few important areas remaining. One of the shortcomings of NSRP-Lite is that in the case of failover, any existing session and VPN information (among other things) is lost. Juniper/NetScreen has an answer to this problem as well. It is called RTO mirroring, and is only available with the full NSRP.
A second shortcoming of NSRP-Lite is that in an NSRP cluster, one firewall ends up sitting unutilized for most of the time. It can be hard to justify the purchase of an additional firewall when management counters with the argument, "It says here that it will not actually be used. Why do you expect me to spend $$$ on something that will not be used?" The setups we have looked at so far are what are referred to as Active/Passive setups one firewall is active and the other is passive. NSRP provides the ability to create Active/Active configurations, in which both firewalls actively handle traffic. Designing the network for Active/Active setups requires careful consideration, but once you have it set up and working, your network will run very nicely.
In this section, we also examine a full-mesh setup, where we combine just about everything that has been discussed in this chapter into one concrete example. Let's start by looking at RTO mirroring.
As mentioned throughout this chapter, a failover between two firewalls can be very disruptive;