ā08-03-2022 06:16 AM
Hi,
We have an issue where we have two fpr2100's in HA mode connected to a stack of switches which are then on a fibre ring.
Currently the HA cables are connected to the primary switch in each of the stacks, which work until one of the primary switches fails.
in this situation the firewalls both become master and all hell breaks lose on the network.
what I am hoping for is that if a member of the switch stack dies, then the whole switch stack stop processing data. Now i understand the idea of the switch stack is to keep going, but does anybody know of a setting or something that can be done?
many thanks,
Mark.
Solved! Go to Solution.
ā08-03-2022 07:05 AM
In order for the firewall clustering to work correctly, you need a direct link between the 2 firewalls. I also, think if you connect all the HA links to only one stack, it would be a simpler design, but that would mean you need fiber between the stacks.
HTH
ā08-03-2022 06:41 AM
Hi,
Can you post a simple diagram showing how the stacks are connected to the FWs for both data traffic and HA?
Are the firewalls in active/passive mode?
HTH
ā08-03-2022 06:50 AM
ā08-03-2022 07:05 AM
In order for the firewall clustering to work correctly, you need a direct link between the 2 firewalls. I also, think if you connect all the HA links to only one stack, it would be a simpler design, but that would mean you need fiber between the stacks.
HTH
ā08-03-2022 07:07 AM
Thankyou for your reply, but we are having to look at all failure modes, and if that fibre failed between the firewalls for the HA, we would be in the same situation so we are trying to work something out 'outside of the box' as they say.
As when the fault happens the whole network basically is knackered...
ā08-03-2022 07:14 AM
Go through this document. It will help you get the two 2100s connected in HA. You are missing some connection. One is the heartbeat. You can use a simple switch or cross the connection between the 2100s.
ā08-05-2022 01:36 AM
Thankyou for the replies everyone, still no further as this is just what is listed on Cisco site.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide