01-24-2021 06:33 AM
Does anyone know if can connect to Checkpoint Firewall in active/standby mode using two different port-channel groups to (each port-channel to a different 9500) to a pair of 9500 configured with SWV?
When running on the primary Checkpoint, there are some performance issues and when failing to the standby, it works fine. The topology is provided here.
01-24-2021 09:00 AM - edited 01-24-2021 09:01 AM
Cat 9500 StackWise virtual means (Physically 2, but logically 1)
So you will not get high availability based on the diagram
instead, i suggest making a dual-homed connection will be good from the design point of view.
CP Primary - 2 Link to to SWITCH1
CP Primary - 2 Link to to SWITCH2
CP Secondary - 2 Link to to SWITCH1
CP Secondary - 2 Link to SWITCH2
This will give high resilience in terms of connectivity and failure of Stachwise virtual.
If they are all in 1 Location, Make sure your SYNC Link dedicated between CP Primary to CP Seconday.
01-24-2021 11:37 AM
01-24-2021 12:48 PM - edited 01-24-2021 12:48 PM
Sure that also consider as a Failure case - i agree with you, since we dont know rest of the network, in general practice we do dual home for suggested design, some case we consider.
is your cp cluster xl ? secure xl ? core xl ? design also refer them your vss / svl.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide