cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1505
Views
0
Helpful
2
Replies

HSRP between 2 routers with VRRP

ohareka70
Level 3
Level 3

I have 2 routers which sit outside my network that i want to connect directly into the firewall. CPE Router 1 is the active router and CPE Router 2 is the secondary. I have HSRP installed between CPE Router 1 and CPE Router 2. CPE Router 1, CPE Router 2 and the HSRP ip addresses are all on the same subnet. They will both talk to the same servers inside my firewall.

Do i need to have VRRP on the firewall to make this scenario work?  or will i need a switch between the firewall and the 2 x Routers

Q.  Whats the best way to do this?  I have been given some advice that i should disconnect the 2 CPE Routers from the Firewall, and place a Network Switch / VLAN a segment to use for the connection between the Firewall and the 2 CPE devices.

1 Accepted Solution

Accepted Solutions

ravikantt
Level 1
Level 1

HI Kevin,

there should be L2 connectivity between HSRP peers, which is missing over here.

Plus, you can't  make inter-work HSRP on router side & VRRP on firewall side.

option 1: Get direct link betwwen CPE 1 & CPE 2

option 2: Use L2 switch & CPE1 & CPE2 via this

for HSRP, VRRP; you have chosse one of the option & recommeded is option 2 (although it'd involve little more cost)

but will in tshoot, if anything goes wroung.

Cheers

Ashok

View solution in original post

2 Replies 2

ravikantt
Level 1
Level 1

HI Kevin,

there should be L2 connectivity between HSRP peers, which is missing over here.

Plus, you can't  make inter-work HSRP on router side & VRRP on firewall side.

option 1: Get direct link betwwen CPE 1 & CPE 2

option 2: Use L2 switch & CPE1 & CPE2 via this

for HSRP, VRRP; you have chosse one of the option & recommeded is option 2 (although it'd involve little more cost)

but will in tshoot, if anything goes wroung.

Cheers

Ashok

Thanks for your help.  I plugged the two routers into a switch which then plugged into the firewall and HSRP works fine.

Cheers
Kevin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card