10-09-2020 07:22 AM
Hello, I’m reaching out to get some expertise advise on how to proceed with adding a second email security appliance C300V on VMWare for redundancy/cluster. We currently have a C300V in production and I want to add another one for a cluster. Also we have a new network solution “Nutanix” that is running hypervisor and would like to see if that platform is supported. Any deployment recommendations with limited impact would be preferred. Any assistance on this would be greatly appreciated.
Solved! Go to Solution.
10-09-2020 01:17 PM
My recommendation is as follows:
a) decide if you want to run your Nutanix hypervisor with either KVM or VMware vSphere support
b) setup a second Ironport ESA (v300) and request from your networking a dedicated IP address for the ESA management interface and a NATed IP for the outside connection
c) built your new ESA with the latest recommended release
d) upgrade your existing ESA to the same release
e) merge the new Nutanix based ESA with your existing ESA into an ESA application cluster
f) point your external MX to both Nated IP devices
While you could switch traffic to use the new appliance it might be easier to have a cluster first so that all configurations will be available on both appliances. From now on your Nutanix folks can use ESX vMotion to move your ESA's around, assuming their setup supports the correct VLAN's.
The Ironport ESA will use the management port of the appliances for the application heartbeat, so no dedicated is required and even recommended.
I hope that helps
-Marc Luescher
10-09-2020 01:17 PM
My recommendation is as follows:
a) decide if you want to run your Nutanix hypervisor with either KVM or VMware vSphere support
b) setup a second Ironport ESA (v300) and request from your networking a dedicated IP address for the ESA management interface and a NATed IP for the outside connection
c) built your new ESA with the latest recommended release
d) upgrade your existing ESA to the same release
e) merge the new Nutanix based ESA with your existing ESA into an ESA application cluster
f) point your external MX to both Nated IP devices
While you could switch traffic to use the new appliance it might be easier to have a cluster first so that all configurations will be available on both appliances. From now on your Nutanix folks can use ESX vMotion to move your ESA's around, assuming their setup supports the correct VLAN's.
The Ironport ESA will use the management port of the appliances for the application heartbeat, so no dedicated is required and even recommended.
I hope that helps
-Marc Luescher
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide