Two Tier MLAG + router redundancy
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎04-12-2019 10:12 AM
Hi there!
For one of my customers I implemented Two-Tier MLAG on four X460-G2 switches based on the KB article: https://extremeportal.force.com/ExtrArticleDetail?an=000082635
Here is my diagram:
MLAG between all switches works like a charm, but I have doubts about how to connect two firewalls (those two onthe top) to my Data Center mesh...
What would be Your sugestion about implementation of two Palo Alto firewalls to provide the maximum redundancy? Both Palo Alto firewalls are running in Active-Pasive HA.
With regards,
Konrad
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎04-12-2019 03:08 PM
If the Firewall is LACP capable than I would suggest to connect each with MLAG to the two switches at the local data centre.
If one switch fails than nothing happens to the firewall connection. If one data centre fails than the HA peer of the Firewall should take over.
If one switch fails than nothing happens to the firewall connection. If one data centre fails than the HA peer of the Firewall should take over.
