cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
878
Views
5
Helpful
8
Replies

routing help

bluesea2010
Level 5
Level 5

Hi, I have two different sites, but I have only two firewalls, so want to deploy active-standby,

if site b internet traffic has to go through site b active fw , if site a fw fails ,site b fw should be active and all internet traffic has to go through the site b

active passive.JPG

How can I do this

What are the pros and cons

Thanks

8 Replies 8

my suggestion is to use 2 firewalls independently on 2 sites. you can use route metric customizations to do route prioritization. 

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Hi,

Thanks . if site A both firewall failed , how  can  I  send the  internet traffic to site b . 

And If site A  wan connection failed but firewall active , how can I send to site B

Thanks

you need 2 internet connections for 2 sites. 

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Hi,

If no redundant isp then?

Thanks 

if sites are placed in distant places, you must have 2 connections for both sites. because if 1 site goes down, all the links are unusable. so you need secondary set of links to get access.

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Hi,

I think my question was not clear , the connectivity between sites are ok and both sites firewall are up.But in site b the isp is down .

So I want all internet traffic from site a to site b.

How can I do that 

Thanks

Hello,

 

how are the sites connected to the firewalls ? The easiest would probably be to implement SLAs on boyh sides that track the availability of the firewalls, and if there is no reachability, simply reroute all traffic using static routes...

Hello
If a site isp link fails then how do you connect to the other site?
If you don’t have any resilient connection the site that’s fails is isolated, As such you cannot have any form of HA redundancy.


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul