03-11-2015 01:03 AM - edited 03-07-2019 11:02 PM
It is possible to setup as attached network? The firewall is checkpoint.
Thank you.
Solved! Go to Solution.
03-13-2015 05:53 AM
Then no you can't make it redundant.
From a Cisco perspective what you need are two switches that can stack then you can run an etherchannel to the stack and spread the ports over both switches.
Or buy another firewall.
Jon
03-11-2015 06:39 AM
So you want the firewall to connect to both switches using an etherchannel, is that correct ?
If so what are the switches ?
Jon
03-11-2015 06:12 PM
Yes, firewall will create an aggregation port and assign an ip address, and connect to 2x layer 2 switches (Cisco 2960), which is access port, then the bottom core switch will create interface vlan with HSRP. So will there be any issue to ping from core switch to firewall aggregation port?
03-11-2015 11:11 PM
It is alright as long as the switches are in stack.
03-12-2015 02:32 AM
unfortunately these switches can't be stack, so the answer is can't setup as the diagram?
03-12-2015 04:55 AM
No you can't because an etherchannel cannot span multiple separate switches.
You need the switches to be stacked as Rejohn says, or 4500/6500 running VSS or Nexus with vPC.
What are the core switches and do they match any of the above ?
Jon
03-12-2015 06:13 PM
Our core switch is not able to stack as well...So is there any way to create the redundancy in between the single firewall and 2 core switches? In case the one of the core switch i still can access to firewall..
03-12-2015 06:44 PM
I haven't done Checkpoints for a long time so don't know what they support.
For example the ASA firewall supports the concept of a redundant interface which means you can pair two interfaces together on the firewall but connect them to different switches.
Only one interface is active unless it fails and then the backup interface can take over.
Is there something similar on your firewall ?
Jon
03-12-2015 06:59 PM
Yes, in checkpoint they do have the similar setup which is called bonding interface with active-backup mode in GAIA OS. My checkpoint is using IPSO OS, and it is not support the bonding interface...
03-13-2015 05:53 AM
Then no you can't make it redundant.
From a Cisco perspective what you need are two switches that can stack then you can run an etherchannel to the stack and spread the ports over both switches.
Or buy another firewall.
Jon
04-06-2016 04:28 AM
Hi vovochka83,
I have similar problem too. We have a checkpoint firewall that I want to connect to two switches and the LAN behind firewall should be learned through OSPF in the cisco switches.
I am thinking that the two switches should run HSRP and the gateway for the firewall is the HSRP Vip. However I also want to run the OSPF between the firewalls and the Switches so that the switches know the LAN behind firewalls via ospf.
appreciate your help in advance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide