cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6221
Views
0
Helpful
10
Replies

Single firewall connect to 2 core switches

vovochka83
Level 1
Level 1

It is possible to setup as attached network? The firewall is checkpoint.

Thank you.

1 Accepted Solution

Accepted Solutions

Then no you can't make it redundant.

From a Cisco perspective what you need are two switches that can stack then you can run an etherchannel to the stack and spread the ports over both switches.

Or buy another firewall.

Jon

View solution in original post

10 Replies 10

Jon Marshall
Hall of Fame
Hall of Fame

So you want the firewall to connect to both switches using an etherchannel, is that correct ?

If so what are the switches ?

Jon

Yes, firewall will create an aggregation port and assign an ip address, and connect to 2x layer 2 switches (Cisco 2960), which is access port, then the bottom core switch will create interface vlan with HSRP. So will there be any issue to ping from core switch to firewall aggregation port?

It is alright as long as the switches are in stack.

Please rate replies and mark question as "answered" if applicable.

unfortunately these switches can't be stack, so the answer is can't setup as the diagram? 

No you can't because an etherchannel cannot span multiple separate switches.

You need the switches to be stacked as Rejohn says, or 4500/6500 running VSS or Nexus with vPC.

What are the core switches and do they match any of the above ?

Jon

Our core switch is not able to stack as well...So is there any way to create the redundancy in between the single firewall and 2 core switches? In case the one of the core switch i still can access to firewall..

I haven't done Checkpoints for a long time so don't know what they support.

For example the ASA firewall supports the concept of a redundant interface which means you can pair two interfaces together on the firewall but connect them to different switches.

Only one interface is active unless it fails and then the backup interface can take over.

Is there something similar on your firewall ?

Jon

Yes, in checkpoint they do have the similar setup which is called bonding interface with active-backup mode in GAIA OS. My checkpoint is using IPSO OS, and it is not support the bonding interface...

Then no you can't make it redundant.

From a Cisco perspective what you need are two switches that can stack then you can run an etherchannel to the stack and spread the ports over both switches.

Or buy another firewall.

Jon

Hi  vovochka83,

I have similar problem too. We have a checkpoint firewall that I want to connect to two  switches and the LAN behind firewall should be learned through OSPF in the cisco switches.

I am thinking that the two switches should run HSRP and the gateway for the firewall is the HSRP Vip. However I also want to run the OSPF  between the firewalls and the Switches so that the switches know the LAN behind firewalls  via ospf.

appreciate your help in advance.

Review Cisco Networking for a $25 gift card