HA Configurations in Strata Cloud Manager (SCM) with NGFW.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

HA Configurations in Strata Cloud Manager (SCM) with NGFW.

Cyber Elite
Cyber Elite

Good Day fellow techies

 

I am writing this article because I was very confused at the SCM tech writing of the Admin Guide, in regards to HA.

I REALLY tried to follow along with the steps, but could not understand.  I think I am not the only one.

 

So, in basic terms, create your folder structure as you would for NGFW FWs, that you will be managing with SCM.

 

For me, I ignore putting anything in the highest (parent) folder of All Firewalls.

 

I created a folder (LIB Firewalls) in SCM, and put 2 FWs in that folder (FW-A and FW-B)

 

SCantwell_0-1730985799439.png

 

I created my variable and interfaces in the parent LIB Firewalls folder. (not shown here)

 

SCM documentation then states you should be able to configure your HA from your Configuration Scope, but there is something missing....

 

A better clarification is to go to the actual FW-DEVICE (FW-A and FW-B).

SCantwell_1-1730984808101.png

 

This is my "before" picture  (I want to have eth1/3 and eth1/4 used for HA) 

Notice that eth 3 and eth 4 show as Not Configured.

SCantwell_2-1730984845856.png

 

I clicked on ethernet1/3

SCantwell_3-1730984916648.png

 

When you add your interfaces (which will be only for HA in my example ), you are presented with the ADD Ethernet window,

 

SCantwell_4-1730984953665.png

(Viola!) this is where you see the mysterious Interface Type with a radio button of Default. 

You do not need to do anything anything, just hit OK, and the interface is now created (in the device folder itself). 

 

Do this for your 2nd interface...and......

 

(This is my "after".  Notice that now eth 3 and eth 4 currently show Auto (for Link Status)

SCantwell_5-1730985007818.png

 

Now you can come back to Configuration Scope for the parent folder (LIB Firewalls) and finish your configuration for HA with variables or IPs or whatever you need.

Thanks to Rae A (at TAC), who was wonderful and helped me in about 3 minutes, after needing to lab this out herself  😛

 

 

 

Please help out other users and “Accept as Solution” if a post helps solve your problem !
0 REPLIES 0
  • 476 Views
  • 0 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!