I think that this solution is not valid because in the configuration each subinterface needs an IP. For example (belongs VSD 0)set interface ethernet0 / 0.99 ip X.Y.Z.32/24 (belongs VSD 0)set interface ethernet0 / 0.99 route (belongs VSD 1)set interface ethernet0 / 0.99: 1 ip X.Y.Z.30/24 (belongs VSD 1)set interface ethernet0 / 0.99: 1 route (belongs VSD 2)set interface ethernet0 / 0.99: 2 ip X.Y.Z.29/24 (belongs VSD 2)set interface ethernet0 / 0.99: 2 route (belongs VSD 3)set interface ethernet0 / 0.99: 3 ip X.Y.Z.31/24 (belongs VSD 3)set interface ethernet0 / 0.99: 3 route They also share the same security policies, objects, and the rest of the configuration. And the cluster configuration is active / active. VSD 0 and 2 are active on firewall A and passive on firewall B. AND VSD 1 and 3 are active on firewall B and passive on firewall A. https://kb.juniper.net/InfoCenter/index?page=content&id=KB7051&cat=NS_204&actp=LIST
... View more