09-04-2014 08:24 PM
For this scenario, assume a simple setup. Two firewalls in HA and two switches in a stack. Also assume the firewalls are in active/passive. Consider the below setup, each firewall has one physical link to separate switch members of the stack.
In this configuration, if switch member 1 fails and firewall 1 is the active firewall, does it automatically failover to firewall 2 if there is no link/path monitoring configured? Or are we to assume that without link/path monitoring, switch 1 failing and firewall 1 would remain active firewall and traffic to the internet would fail?
I typically always use the below configuration. Each switch has a port aggregate (802.3ad) and 1 connection in that LAG connects to each member switch. This utilizes double the ports but I was under the assumption the first scenario would only work with link/path monitoring. I also typically do the design so I can withstand any firewall failing AND any switch failing at the same time.
Finally, in the bottom configuration, does anyone have recommendation as far as setting up distribution configs on the switch side? (eg. mac src / dest). Are those needed?
09-05-2014 06:55 AM
Hi Mack,
I confirm 100% Internal to External Traffic will not flow, and secondary remains in passive state.
Regards,
Hardik Shah
09-05-2014 06:57 AM
Thank you!
Can you provide insight in regards to my question for scenario 2?
"Finally, in the bottom configuration, does anyone have recommendation as far as setting up distribution configs on the switch side? (eg. mac src / dest). Are those needed?"
09-05-2014 06:57 AM
Hi Mack,
ITs wise to configure interface monitoring, only in few circumstance people dont configure it.
Do you have any reason for not to configure it?
Regards,
Hardik Shah
09-05-2014 07:02 AM
Hi Mac,
Lets say you have implemented scenario 2, then cabling is good on Switch. You dont need any cabling changes.
However, Ports connected with Firewall remains in Access VLAN of Trust interface.
Let me know if that answers your query.
Regards,
Hardik Shah
09-05-2014 07:31 AM
And Inteface on the firewall should be aggregated interface in L3 Mode with an IP address.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!