VLANs for HA links

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VLANs for HA links

L1 Bithead

Hi all,

 

I am configuring two PA 3060 in A/A HA across datacenter. All the HA links from a PA in a DC will be connected to the core switch. Is it possible to put all HA links, i.e., HA1, HA2, HA3, HA1-backup, HA2-backup, in a single VLAN? Or does each link needs a separate VLAN?

 

Thanks

1 accepted solution

Accepted Solutions

L6 Presenter

Especially in a A/A enviornment would you want to deploy something which isn't considered "best practice" from a vendor?

 

I've never tried to use all connections on a single VLAN, but I'd suspect the FW would take the config.

 

 

The concern would probably be the vulnerability in collapsing everything into a single VLAN and the amount of traffic this would be.

View solution in original post

4 REPLIES 4

L1 Bithead

Hi

 

As far as i know all HA links are expected to be  in a sepperate ethernet segment. You can do this bij sepperate cables or bij seperate vlans for each ha type traffic. If you are stretching accros a data center, maybe it is wise to consider building the HA on L3 : L3 HA

 

hope this helps

L6 Presenter

Especially in a A/A enviornment would you want to deploy something which isn't considered "best practice" from a vendor?

 

I've never tried to use all connections on a single VLAN, but I'd suspect the FW would take the config.

 

 

The concern would probably be the vulnerability in collapsing everything into a single VLAN and the amount of traffic this would be.

I'm going to go with @Brandon_Wertz on this one. TAC generally doesn't love touching A/A configurations in my experiance, if you through this in the lope they are likely going to point to misconfiguration if you ever contact them on any issues with HA. I imagine that the firewall would except the configuration but it's likely just better to do it 'by the books' on this one to avoid any issues popping up.

I could not find anything in the guides that each of these links should be in a separate VLAN.

Sure my first though was to configure separate VLANs but wanted to know whether this will work without issues. Then there is TAC support issue!

 

Thanks all!

  • 1 accepted solution
  • 3213 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!