Hi Davide,
thanks for your quick response.
Our firewalls are working in an active-passive scenario and they are interconnected over a heartbeat-link.
Each firewall is a standalone unit.
So in this scenario, I could configure MLAG on the VSX-Stack to both firewalls?
Regards
------------------------------
Chris vBargen
------------------------------
Original Message:
Sent: Feb 25, 2021 10:28 AM
From: Davide Poletto
Subject: VSX Stack to firewall
Hi Chris,
"What is the best way to do this, MLAG to both Firewalls?"
before answering that question let me instead to highlight an aspect of your scenario: can your Cluster of Firewalls be seen as a single (unique) logical entity from the VSX point of view? I mean...generally an Firewall HA solution (Active/Active or Active/Passive, it doesn't matter) is made of two standalone units interconnected with an heartbeat link...and this pair of Firewall units generally can't be seen as a single logical entity (think about: can you freely terminate/distribute link aggregation's members originating on the VSX or on a singel standalone Switch to both the HA Cluster's members concurrently?).
------------------------------
Davide Poletto
Original Message:
Sent: Feb 25, 2021 09:17 AM
From: Chris vBargen
Subject: VSX Stack to firewall
Hi guys,
I want to configure an aruba VSX Stack as cores-switches. The access-switches should be connected via MLAG to the VSX Stack and therefore I want to use the active gateway configuration for routing.
Now I want to connect the VSX Stack to our Firewall-HA.
What is the best way to do this, MLAG to both Firewalls?
------------------------------
Chris
------------------------------