06-18-2013 06:15 AM - edited 03-04-2019 08:14 PM
I have 2 routers which sit outside my network that i want to connect directly into the firewall. CPE Router 1 is the active router and CPE Router 2 is the secondary. I have HSRP installed between CPE Router 1 and CPE Router 2. CPE Router 1, CPE Router 2 and the HSRP ip addresses are all on the same subnet. They will both talk to the same servers inside my firewall.
Do i need to have VRRP on the firewall to make this scenario work? or will i need a switch between the firewall and the 2 x Routers
Q. Whats the best way to do this? I have been given some advice that i should disconnect the 2 CPE Routers from the Firewall, and place a Network Switch / VLAN a segment to use for the connection between the Firewall and the 2 CPE devices.
Solved! Go to Solution.
06-18-2013 07:01 AM
HI Kevin,
there should be L2 connectivity between HSRP peers, which is missing over here.
Plus, you can't make inter-work HSRP on router side & VRRP on firewall side.
option 1: Get direct link betwwen CPE 1 & CPE 2
option 2: Use L2 switch & CPE1 & CPE2 via this
for HSRP, VRRP; you have chosse one of the option & recommeded is option 2 (although it'd involve little more cost)
but will in tshoot, if anything goes wroung.
Cheers
Ashok
06-18-2013 07:01 AM
HI Kevin,
there should be L2 connectivity between HSRP peers, which is missing over here.
Plus, you can't make inter-work HSRP on router side & VRRP on firewall side.
option 1: Get direct link betwwen CPE 1 & CPE 2
option 2: Use L2 switch & CPE1 & CPE2 via this
for HSRP, VRRP; you have chosse one of the option & recommeded is option 2 (although it'd involve little more cost)
but will in tshoot, if anything goes wroung.
Cheers
Ashok
06-18-2013 03:19 PM
Thanks for your help. I plugged the two routers into a switch which then plugged into the firewall and HSRP works fine.
Cheers
Kevin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide