FAIL OVER SWITCHs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

FAIL OVER SWITCHs

L3 Networker

Hi guys ,

i want to explain my problem.

I have a 2 switches in fail over with link aggregate with 3 vlan`s. (LAN , SAN , Management)

I have one PA-500.

So

How can i configure my PAN interfaces , when 1 switch fail , the 2 switch get all flow and my firewall need to answer my requests. PAN 500 is my Default gateway on my LAN , SAN , Management

In this picture we can understand better my toplogy http://www.google.com.br/imgres?q=Firewall+with+2+switches&um=1&hl=pt-BR&client=safari&rls=en&biw=12...


best Regards

Thiago Lima.

9 REPLIES 9

L6 Presenter

Hi...You can configure two L2 interfaces on the PA500 with L3 forwarding and VLAN tagging to support your VLANs.  Define virtual L3 interfaces, one per VLAN, which will act as the default gateway for all users/devices.

Since you have 2 switches for failover, you should consider adding a 2nd PA500 for high availability.  Otherwise if the PA500 is unavailable, your services will be interrupted.

Thanks.

About port channel , it`s possible to do ? with cisco ?

Best Regards.

Thiago Lima.

Yes you can do port aggregation between PAN and a switch.

For example following setup:

PAN1 - 2 cables - SWITCH1

PAN2 - 2 cables - SWITCH2

SWITCH1 - 2 cables - SWITCH2

See following threads for more info regarding aggregated interfaces:


Aggregation of ethernet on PA-4050 with Cisco switch
https://live.paloaltonetworks.com/message/2388#2388


PA 5050 Aggregate Interfaces
https://live.paloaltonetworks.com/message/13551#13551

The PA500 does not support link aggregation at this time.  Thanks.

Only 4000 Series and 5000 Series Support Port Channel ?

Best Regards.

Thiago Lima.

Correct.

oops...

?????

I had missed that currently only 4000 and 5000 series support aggregated interfaces.

  • 3666 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!