Hi guys ,
i want to explain my problem.
I have a 2 switches in fail over with link aggregate with 3 vlan`s. (LAN , SAN , Management)
I have one PA-500.
How can i configure my PAN interfaces , when 1 switch fail , the 2 switch get all flow and my firewall need to answer my requests. PAN 500 is my Default gateway on my LAN , SAN , Management
In this picture we can understand better my toplogy http://www.google.com.br/imgres?q=Firewall+with+2+switches&um=1&hl=pt-BR&client=safari&rls=en&biw=12...
Hi...You can configure two L2 interfaces on the PA500 with L3 forwarding and VLAN tagging to support your VLANs. Define virtual L3 interfaces, one per VLAN, which will act as the default gateway for all users/devices.
Since you have 2 switches for failover, you should consider adding a 2nd PA500 for high availability. Otherwise if the PA500 is unavailable, your services will be interrupted.
Yes you can do port aggregation between PAN and a switch.
For example following setup:
PAN1 - 2 cables - SWITCH1
PAN2 - 2 cables - SWITCH2
SWITCH1 - 2 cables - SWITCH2
See following threads for more info regarding aggregated interfaces:
Aggregation of ethernet on PA-4050 with Cisco switch
PA 5050 Aggregate Interfaces
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!