- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-03-2012 08:06 AM
Hi guys ,
i want to explain my problem.
I have a 2 switches in fail over with link aggregate with 3 vlan`s. (LAN , SAN , Management)
I have one PA-500.
So
How can i configure my PAN interfaces , when 1 switch fail , the 2 switch get all flow and my firewall need to answer my requests. PAN 500 is my Default gateway on my LAN , SAN , Management
In this picture we can understand better my toplogy http://www.google.com.br/imgres?q=Firewall+with+2+switches&um=1&hl=pt-BR&client=safari&rls=en&biw=12...
best Regards
Thiago Lima.
04-03-2012 09:37 AM
Hi...You can configure two L2 interfaces on the PA500 with L3 forwarding and VLAN tagging to support your VLANs. Define virtual L3 interfaces, one per VLAN, which will act as the default gateway for all users/devices.
Since you have 2 switches for failover, you should consider adding a 2nd PA500 for high availability. Otherwise if the PA500 is unavailable, your services will be interrupted.
Thanks.
04-03-2012 11:03 AM
About port channel , it`s possible to do ? with cisco ?
Best Regards.
Thiago Lima.
04-03-2012 12:28 PM
Yes you can do port aggregation between PAN and a switch.
For example following setup:
PAN1 - 2 cables - SWITCH1
PAN2 - 2 cables - SWITCH2
SWITCH1 - 2 cables - SWITCH2
See following threads for more info regarding aggregated interfaces:
Aggregation of ethernet on PA-4050 with Cisco switch
https://live.paloaltonetworks.com/message/2388#2388
PA 5050 Aggregate Interfaces
https://live.paloaltonetworks.com/message/13551#13551
04-03-2012 01:14 PM
The PA500 does not support link aggregation at this time. Thanks.
04-03-2012 01:16 PM
Only 4000 Series and 5000 Series Support Port Channel ?
Best Regards.
Thiago Lima.
04-03-2012 01:28 PM
I had missed that currently only 4000 and 5000 series support aggregated interfaces.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!