Showing results for 
Search instead for 
Did you mean: 

Request suggestion on the Design

Level 3
Level 3


Kindly find attached the network diagram. I need the below functionality from the proposed setup. Kindly sugegst me with your findings:


1. Both the internet links will be Active/Active

2. I have kept both the link load balancers in Active/Standby mode

3. I have kept both the Perimeter firewalls in Active/Standby mode

4. I have kept both the Internet firewalls in Active/Standby mode

5. Core switches are configured in HSRP

6. All users are connected to core switch via access switches

7. IPS should be placed in In-Line mode & it should inspect outbound internet traffic, traffic destined to DMZ, traffic destined to internet server segment

Kindly suggest if this setup is gona work, also suggest your findings..

3 Replies 3

Marwan ALshawi
VIP Alumni
VIP Alumni

as a high level it looks ok

however yo mentioned that both Internet edge routers will be working in active/active while the other devices HA will be working in active/standby  jut you need to make sure that the returning traffic from the Internet will take the right path

also make sure that one any device int he path like IPS, FW or a L3 switch gose down the redundant path can handle the traffic load

also the DMZ switches it is better to have them inter connected like other switches in the network so that in the case of uplink down of th primary switch this link can be used to reroute the traffic

have a look at the bellow link for some more details and ideas

Campus Network for High Availability Design Guide


if helfpul Rate


As said, it looks like high redundancy in this case I would prefer both the Internet facing firewalls in Active/Active mode (high availability) which connected to your HSRP core switches.

And connect your LAN switches (to which your internal servers connected) with two uplinks one to each HSRP core switches so that if on core switch is down in case then the other can take the path.

And what type of those switches? to which your Firewall-1 and Firewall-2 connected (not core switches). If you connect those two switches back to back make sure they will not create any loop as in some cases they will create loop.

Please rate the helpfull posts.

Hi Naidu,

The switch before link load balancer is L2, rest all switches are L3 capable.



Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card