FAIL OVER SWITCHs

Reply
Highlighted
L3 Networker

FAIL OVER SWITCHs

Hi guys ,

i want to explain my problem.

I have a 2 switches in fail over with link aggregate with 3 vlan`s. (LAN , SAN , Management)

I have one PA-500.

So

How can i configure my PAN interfaces , when 1 switch fail , the 2 switch get all flow and my firewall need to answer my requests. PAN 500 is my Default gateway on my LAN , SAN , Management

In this picture we can understand better my toplogy http://www.google.com.br/imgres?q=Firewall+with+2+switches&um=1&hl=pt-BR&client=safari&rls=en&biw=12...


best Regards

Thiago Lima.

Highlighted
L6 Presenter

Re: FAIL OVER SWITCHs

Hi...You can configure two L2 interfaces on the PA500 with L3 forwarding and VLAN tagging to support your VLANs.  Define virtual L3 interfaces, one per VLAN, which will act as the default gateway for all users/devices.

Since you have 2 switches for failover, you should consider adding a 2nd PA500 for high availability.  Otherwise if the PA500 is unavailable, your services will be interrupted.

Thanks.

Highlighted
L3 Networker

Re: FAIL OVER SWITCHs

About port channel , it`s possible to do ? with cisco ?

Best Regards.

Thiago Lima.

Highlighted
L6 Presenter

Re: FAIL OVER SWITCHs

Yes you can do port aggregation between PAN and a switch.

For example following setup:

PAN1 - 2 cables - SWITCH1

PAN2 - 2 cables - SWITCH2

SWITCH1 - 2 cables - SWITCH2

See following threads for more info regarding aggregated interfaces:


Aggregation of ethernet on PA-4050 with Cisco switch
https://live.paloaltonetworks.com/message/2388#2388


PA 5050 Aggregate Interfaces
https://live.paloaltonetworks.com/message/13551#13551

Highlighted
L6 Presenter

Re: FAIL OVER SWITCHs

The PA500 does not support link aggregation at this time.  Thanks.

Highlighted
L3 Networker

Re: FAIL OVER SWITCHs

Only 4000 Series and 5000 Series Support Port Channel ?

Best Regards.

Thiago Lima.

Highlighted
L6 Presenter

Re: FAIL OVER SWITCHs

Correct.

Highlighted
L6 Presenter

Re: FAIL OVER SWITCHs

oops...

Highlighted
L3 Networker

Re: FAIL OVER SWITCHs

?????

Highlighted
L6 Presenter

Re: FAIL OVER SWITCHs

I had missed that currently only 4000 and 5000 series support aggregated interfaces.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!