07-02-2020 03:45 AM
Hi,
Is it possible to configure HA cluster where one node has a link to ISP A and second node has a link to ISP B ?
I'm aware of problems with routing configuration but for me it seems possible to achieve.
Anyone did this ?
07-02-2020 01:50 PM
Hi
On HA you can use IP SLA option to achieving that
on FMC
on FDM
regards.
07-02-2020 10:45 PM
Both nodes must have all of their interfaces in the same subnets.
So if you have provider independent addressing and extend the subnet across the WAN you could do it. It would not be a recommended design though.
07-03-2020 12:44 AM
Yes, I know that. But what if I can not stretch WAN vlan to both sites and Firepowers, but I will configure those interfaces neverthelss and firewalls wont see each other on that vlan - I will set them as non-monitored interfeces. Does FTD talk to each other on that type of interface?
So if we have ISP A and ISP B:
I configure ISP-A subinterface on vlan A on both members, but only one of them will be able to communicate with ISP. Node B will be "blind" on that subinterface.
Then I will configure interfaces to ISP B the same way.
Using IP SLA tracking I will be able to change default route when cluster failover.
I absolutely agree that it's not elegant and not recommended but its a backup design if wont be able to build two independent clusters.
07-03-2020 01:55 AM
The problem I see is that IP SLA changing the default route will not trigger a failover event.
So if you lose the site A ISP gateway reachability (or whatever upstream address you have in your IP SLA monitor) and that triggers a default route change, the site A Firepower will remain active but with an unusable default route.
07-06-2020 02:25 AM
Hi,
Marvin good point. And this finishes the discussion I think
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide