Skip to main content
High availability

Two boxes, one job, zero dropped connections

Pair two Firecradle appliances so if one fails, the other takes over in seconds. The part that actually matters: live connections keep running through the switch. A video call, a file upload, or a card payment in progress does not get cut off, because the standby already knows about it.

VRRP shared address · conntrackd connection-state sync

Two appliances, answering as one

Pairing two boxes is how you remove a single point of failure from your network without your team even noticing when it happens.

One active, one standby
Two Firecradle appliances work as a pair. One handles all the traffic, and the other sits ready to take over.
One shared address
Both boxes share a single address, using a standard called VRRP. Your computers only ever talk to that one address.
Invisible switch-over
When the active box fails, the standby answers to the shared address within seconds. Nobody has to change a setting on their laptop.

The part most firewalls get wrong: the connections themselves

Sharing an address is the easy part. The hard part, and the thing that actually matters to your users, is keeping the list of live conversations in sync too, using conntrack.

Live connections survive
The standby box keeps a running copy of every live connection, using conntrackd. A failover does not reset them.
A dedicated sync link
The two boxes talk to each other over their own connection, separate from your normal network traffic.
Priority and preempt
Decide which box should normally be active, and whether it takes back control automatically once it recovers.
Firecradle high availability screen showing a paired appliance with role Active, peer status Standby-ready, VRRP priority, and connection state sync status as In sync
Both boxes, one shared address, connection state kept in sync in the background.

What it runs on

VRRP
Standard shared virtual address between the pair
conntrackd
Keeps live connections synced across both boxes
2 boxes
One active, one standby, ready at all times
Seconds
Typical time for the standby to take over

How people actually use this

A video call that does not drop

The problem: The active firewall fails mid-meeting. On most firewalls, every call, upload, and open connection dies with it.

What Firecradle does:
The standby box takes over the shared address within seconds
conntrackd had already copied the call's connection state across
The call keeps running, because the standby recognizes it as already open
Nobody in the meeting notices anything happened

A payment that is mid-transaction

The problem: A card payment is being processed at the exact moment a firewall appliance loses power.

What Firecradle does:
The paired appliance already had the connection state, kept in sync continuously
The standby answers to the shared address immediately
The in-progress transaction is not treated as a new, unrecognized connection
The payment completes instead of timing out

Everything here is included

No add-on license, no extra box to buy separately

Active/standby pairing between two Firecradle appliances
VRRP shared virtual address, invisible to every device on the network
conntrackd connection-state sync, so live connections survive failover
A dedicated sync link, kept separate from normal traffic
Priority and preempt settings, so you control which box leads
An encrypted, write-only VRRP password
A status page showing which box is active and whether sync is healthy

Common questions

What actually happens when the active box fails?

The standby box notices within seconds and starts answering to the shared address. Because it already has a synced copy of every live connection, existing traffic keeps flowing instead of being dropped and restarted.

Is this different from a normal failover setup?

Most competitors fail over the address but not the connections. That means every open call, transfer, or session drops and has to reconnect from scratch. Firecradle syncs connection state continuously, so it survives the switch.

Do my computers need any special configuration?

No. They only ever talk to the one shared address. Which physical box is answering behind that address is invisible to them.

Is the connection between the two boxes secure?

Yes. The shared-address protocol uses a password that is encrypted at rest and never shown back to you once set, and the two boxes are meant to sync over their own dedicated link, separate from your regular network.

A hardware failure your users never feel

Active/standby pairing with connection-state sync is part of every Firecradle appliance. Try it free for 30 days.

No credit card required · Cancel anytime · 30-day free trial