08-16-2020 08:59 AM
I'm designing an edge network with Active/Active HA. After reading the PA documentation, I found Active/Active Routed based redundancy design which seems best suited for our environment. However the topology shown in Docs is a square model and I'm thinking to add more links to convert it to full mesh to add more redundancy and fast convergence I wanted to ask what are the pros and cons of full mesh design.
Pros of Full mesh ( i can think of): 1) ECMP 2) Fast switchover in case of link failure 3) Tolerate double link failure
Cons of Full mesh: 1) Complexity 2) more physical interfaces 3) Asymetric traffic may cause issue such as traffic leave eth 1/2 but comes back from eth1/4 of the firewalls (assuming eth1/2 & eth1/2 in the same security Zone) and to allow that behavior, I will have to tweak the firewall configuration.
Please see below both square design and the full mesh design that I intend to proceed with.
I will appreciate the feedback. Thanks
08-17-2020 02:13 PM
While I like to keep my networks relatively simple, as you stated there are advantages and disadvantages to either. If you are not concerned with the additional ports used, then go full meshed. The real advantage is device failure. Looks at the diagrams and then pretend a device failed, then find the paths that traffic can flow.
08-18-2020 05:02 PM
If I may ask, what was your business case for using HA-AA with full-meshed routing? The reason I am asking is we just implemented a topology last weekend HA-AS ecmp load balancing and BGP on the external interface of the firewall to ensure complete usage of both the internet links by the customer. And now it is in production and working like a charm. Maybe if you let me know your purpose of Active-Active setup I can advise you better on it.
08-19-2020 06:22 PM
I'm also fan of A/S deployment however for this environment, one primary use case of A/A we have is, we have plenty of available bandwidth but a single Active FW is a bottleneck. We occasionally have high volume of data transfer and we can leverage both active path.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!