01-20-2017 12:22 AM - edited 03-08-2019 08:59 AM
Hi All,
I have a scenario that Two ISRs are connected to a Firewall Cluster. I want to connect the internet routers directly to the Firewall Cluster so that I can save two un-trusted network switches. Bridge Domain Interfaces (BDI) are enabled on each ISR so that Firewall A and B can communicate via service instance 100 and they can reach
However, spanning loop happened when the second ISR is added
Here is my lab configuration on 1 of the ISR.
interface GigabitEthernet0/0/0
description To Untrusted interface of Firewall A
no
negotiation auto
service instance 100 ethernet
encapsulation untagged
l2protocol peer
bridge-domain 100
!
interface GigabitEthernet0/0/1
description To Untrusted interface of Firewall B
no
negotiation auto
service instance 100 ethernet
encapsulation untagged
l2protocol peer
bridge-domain 100
!
interface BDI100
description Untrusted Subnet
no
no
no
!
01-24-2017 04:32 PM
Hi,
Are you deploying the firewalls in transparent mode?
What firewall are you using?
Cheers.
02-15-2017 09:40 PM
It is FortiGate firewall configured as Layer 3 firewall
07-03-2019 12:41 PM
Hi,
Did you ever to get this resolved, I am having some issues with connecting SRX firewalls in a cluster to two ASR 1001 routers.
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide