Configure VPN load balancing

VPN load balancing is a network distribution mechanism that groups two or more Firewall Threat Defense devices to distribute remote access VPN sessions evenly across the group.

How VPN load balancing works

  • One device acts as the director and the remaining devices are members.

  • The director routes incoming sessions to the least-loaded device, optimizing resource usage and improving performance and availability.

  • VPN load balancing is based on session distribution, not throughput or other factors.

VPN load balancing group requirements

  • Groups require two or more Firewall Threat Defense devices that support remote access VPN.

  • Devices in a group do not need to be the same type or run identical software versions or configurations.

  • Firewall Threat Defense devices support VPN load balancing with Secure Client SAML authentication.

  • Devices behind NAT can be part of a load-balancing group.

  • Devices in a high availabilty pair can be part of a load-balancing group.