PA Firewalls HA Active-Active Routed design with BGP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA Firewalls HA Active-Active Routed design with BGP

L0 Member

Hello Everyone,
I'm designing an edge network with Active/Active HA. After reading the PA documentation, I found Active/Active Routed based redundancy design which seems best suited for our environment. However the topology shown in Docs is a square model and I'm thinking to add more links to convert it to full mesh to add more redundancy and fast convergence  I wanted to ask what are the pros and cons of full mesh design. 

 

Pros of Full mesh ( i can think of): 1) ECMP  2) Fast switchover in case of link failure 3) Tolerate double link failure

Cons of Full mesh: 1) Complexity 2) more physical interfaces 3) Asymetric traffic may cause issue such as traffic leave eth 1/2 but comes back from eth1/4 of the firewalls (assuming eth1/2 & eth1/2 in the same security Zone) and to allow that behavior, I will have to tweak the firewall configuration.
Please see below both square design and the full mesh design that I intend to proceed with.

I will appreciate the feedback. Thanks

 

HA-AA-Routed-based-Redundancy-Square

HA-AA-Routed-based-Redundancy-Square.jpg

 

HA-AA-Routed-based-Redundancy-Full-Mesh

HA-AA-Routed-based-Redundancy-Full-Mesh.jpg

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

While I like to keep my networks relatively simple, as you stated there are advantages and disadvantages to either. If you are not concerned with the additional ports used, then go full meshed. The real advantage is device failure. Looks at the diagrams and then pretend a device failed, then find the paths that traffic can flow.

 

Good luck!

L2 Linker

Hi Mate,

 

If I may ask, what was your business case for using HA-AA with full-meshed routing? The reason I am asking is we just implemented a topology last weekend HA-AS ecmp load balancing and BGP on the external interface of the firewall to ensure complete usage of both the internet links by the customer. And now it is in production and working like a charm. Maybe if you let me know your purpose of Active-Active setup I can advise you better on it.



Thanks & Regards,
Varun Rao

@VarunRao 

 I'm also fan of A/S deployment however for this environment, one primary use case of A/A we have is, we have plenty of available bandwidth but a single Active FW is a bottleneck. We occasionally have high volume of data transfer and we can leverage both active path. 

  • 4781 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!