We have already extreme switches 5520 VOSS platform running in vIST mode and connected to firewall (with LACP) on LAN side.
We want to achieve redundancy on DMZ and WAN side as well. I am attaching diagram for reference. We are planning to purchase 5520/5420 for DMZ environment and want to achieve redundancy. I have question regarding design.
1. Should I configure vIST and LACP configuration on DMZ environment? OR
2. I should configure simple LACP and mlt configuration on DMZ switches?
Which option would be the best one?
You should do the same on both sides of the FireWalls for the fastest failover.
You cannot make an LACP connection from a device (e.g. a FireWall, server system, ...) to a NON vIST setup, then the LACP would never form a trunk group..
It must be in a vIST setup.