Thank you for your detailed response and this is very helpful. Obviously I have follow-up questions. 1) I donÕt know why admin guide version 7.0 page 887 and the article KB3179 has a diagram showing as if a/a cluster requires a VIP. So you are saying DNS Name, https://vpn.company.com will point to the external IP addresses of both devices. In this case, SA1 will be contacted first and SA2 will be in failover mode. 2) In the first step, you stated that Ôremove both the active (SA1) and passive (SA2) from the A/P clusterÕ. Instead of removing both, can I just remove the SA2 only so that the SA1 continue to provide service? While the SA1 provide continued services, I can physically move the SA2 to the new data center, the location is about 40 minute drive from where the SA2 is currently located. So far, there is no outage. 3) Once the SA2 is ready at the new data center, can I use the external IP address to test the login to the SA, instead of creating a DNS entry as you mentioned? Same for the SA1, can I use the IP address to test? 4) Once the test is successful, I can go ahead with configuring A/A clustering on SA1 and add the SA2 to the cluster configuration. The DNS name, https://vpn.company.com is pointing to cluster VIP say, 199.199.199.199 in A/S configuration, Can I assign the IP address, 199.199.199.199 to the external interface of the SA1 so that I donÕt have to change the DNS name to point to a different IP address. If I assign 199.199.199.100 to the external interface of the SA2, then I will have to update the DNS name to point to the new IP address, 199.199.199.100. Thanks
... View more