Could multiple InControl servers control the same firewall?

Last modified on 16 Nov, 2022. Revision 9
Explanation about multiple InControl servers with different databases containing the same firewalls.
Up to date for
InControl 3.14.01
Supported since
InControl 1.xx
Status OK
Author
Perter Nilsson

Question:

Is it possible to have multiple InControl Servers with different databases controlling the same firewall? If so, how will the configuration deployments then work?

Answer:

It is technically possible but it should be avoided. InControl is designed as a Client/Server solution where you can connect to the central server using multiple clients. If redundancy is the concern, it would be better to make sure that the central server database is regularly backed up and that the server is adequately protected from environmental hazards, power spikes etc.

It will work having 2 InControl servers but you will most likely get a lot of warnings in the event logs about “changes made by another instance of InControl”. Basically it is not how InControl was designed to be used. Even when using old FineTune it was not recommended to have multiple data sources.

There is no real advantage of using such a setup, it is better to install the client and have it connect to the central node. Then you also avoid problems where 2 users are making changes to the same Firewall at the same time and risk overwriting each others changes.



Related articles

Automatic scheduled backup of InControl server database
5 Feb, 2021 incontrol howto backup windows
Device initiated InControl management of NetWall HA clusters with a single public IP
31 Mar, 2022 incontrol core netcon netwall ha cluster coscore
How to perform an offline installation of InControl
26 Jan, 2022 howto incontrol installation
Probe failed, did not get a result
8 Sep, 2022 incontrol ciphers