08-29-2023 03:30 AM
Hello All,
We have already extreme switches 5520 VOSS platform running in vIST mode and connected to firewall (with LACP) on LAN side.
We want to achieve redundancy on DMZ and WAN side as well. I am attaching diagram for reference. We are planning to purchase 5520/5420 for DMZ environment and want to achieve redundancy. I have question regarding design.
1. Should I configure vIST and LACP configuration on DMZ environment? OR
2. I should configure simple LACP and mlt configuration on DMZ switches?
Which option would be the best one?
08-30-2023 03:52 AM
Hi,
We are already using LACP MLT config on 5520 connected to firewalls with LACP on LAN side. It is working with no issue.
My question here is should I use vIST or simple LACP design for DMZ.
08-30-2023 08:02 AM
Hello,
Yes , you should use vIST setup in the redundant switch on the DMZ side.
Only then you can connect the firewalls and DMZ servers with LACP to the DMZ vIST cluster switches.
regards
WillyHe
08-31-2023 03:29 AM
Ok Thanks
08-30-2023 01:39 AM
Hello,
You should do the same on both sides of the FireWalls for the fastest failover.
You cannot make an LACP connection from a device (e.g. a FireWall, server system, ...) to a NON vIST setup, then the LACP would never form a trunk group..
It must be in a vIST setup.
regards
WillyHe