10-04-2022 02:12 AM - edited 10-04-2022 05:13 AM
Hi All
I have 2 Firepower FTD (2130 models) in HA (high availabilty)mode working well in routed Mode. Its working using ONE protected subnet eg 98.x.x.0/24 for my servers. My servers are reachable from the outside using Public Addresses etc. BUT I have requirement to add a SECOND Subnet eg 49.x.x.0/24 on the same HA pair. is that possible. Logically this leans to BGP to advertise internal Networks. Any Examples or case Studies. So my Current setup below looks something like this ;
98.x.x.3 - 12( Protected Servers)--------98.x.x.1-2(Gw) [{Inside} HA -FTD(2 ftd) {Ouside} ] 69.x.x.1-2--- Static >---69.x.x.250[ Router-ISP ] (WORKING )
REQUIRED
98.x.x.0/24 and 49.x.x.0/24( Protected Servers)--------98.x.x.1-2(Gw) [{Inside} HA -FTD(2 ftd) {Ouside} ] 69.x.x.1-2--- Static >---69.x.x.250 [Router-ISP ]
Please Assist
Solved! Go to Solution.
10-10-2022 09:27 AM
We managed to get working using IGP in our case it was OSPF used to advertise routes. I had made a mistake saying Subinterfaces dont work... It was just my wrong interpretation. Sub interfaces dont work on the failover link only.
10-04-2022 03:28 AM
but config subinterface in FTD can solve issue this make FTD have one subinterface for each subnet.
10-04-2022 05:12 AM - edited 10-04-2022 05:15 AM
Unfortunately you cannot use subinterfaces in high availability mode.
10-10-2022 09:27 AM
We managed to get working using IGP in our case it was OSPF used to advertise routes. I had made a mistake saying Subinterfaces dont work... It was just my wrong interpretation. Sub interfaces dont work on the failover link only.
10-10-2022 10:10 AM
So glad your issue solve.
Good luck freind
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide