cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
266
Views
0
Helpful
1
Replies

switch/router connecting to firewall

wecheng
Level 1
Level 1

Hi all,

We have a Cisco switch which has 2 ports connected to 2 legs of a CheckPoint firewall HA cluster.

Cluster A has, for example 192.168.1.25 00:A0:C9:E8:C7:7F 192.168.1.1 in its local.arp file

and cluster B has 192.168.1.25 00:A0:C9:E8:CB:3D 192.168.1.2 in its local.arp file

where 192.168.1.25 is the virtual NAT.

192.168.1.1 & 192.168.1.2 are the dedicated physical interface IP on cluster A & B respectively.

Question is: Is the switch/router getting confused by same Nated IP but different MAC address.

Thanks

1 Reply 1

ebreniz
Level 6
Level 6

Did you get any message say STP or duplicate mac address, You can use show ip arp and see if the duplicate address is there.

I think this can be done in a different way. I think SLB will work.

http://www.cisco.com/en/US/products/hw/switches/ps672/products_configuration_guide_chapter09186a008007f244.html

Review Cisco Networking for a $25 gift card