08-12-2022 02:21 AM
Hello guys,
I have a a question regarding network security using firewalls like FTD and FMC.
Can I have like this kind of topology and if I do can then how many outside zone and Inside zone should I have.
My purpose is just to have a redundant links for each device. Can someone please help me out?
08-12-2022 03:20 AM
for FTD HA you need L2 SW in OUT of FTD, that mandatory for HA in FTD
08-12-2022 03:33 AM
For inside, you are likely good with one logical inside interface that consists of two Etherchannel members. Your internal switch has to be one logical system for that (stack, VSS, VCP, ...).
For outside, you have to make sure that both devices outside1 goest to ISP1 and both outside2 go to ISP2. That is different in your drawing. And the interfaces on both devices (like outside1 on device one and device 2) need to be L2 adjacent Which means the two links on the Routers have to end up in a single VLAN.
02-10-2023 06:12 AM
I'm in the process of designing this now. Can you connect a FTD HA pair's outside interfaces to two disparate L2 switches? I don't want to use StackWise on my WAN switches because any software upgrades will require the entire stack to reboot. But with FTD not supporting redundant interfaces, I don't see how else I can connect them.
02-10-2023 06:20 AM
Yes, I typically use two 10-Port Catalyst 1000 or CBS350 for the WAN-Switches:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide