JuniperForum.com
July 29, 2010, 07:50:36 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: HA without a dedicated port for HA  (Read 825 times)
buntit
Newbie
*
Posts: 2


View Profile
« on: September 29, 2009, 09:49:30 PM »

Hi to all! I am just a newbie w/ Juniper Netscreen. I came here to seek advice and correct my understanding if I am wrong. Thanks in advance.

SCENARIO: I got 2 Netscreen SSG 320M. 4 of the ports are being used by customer for trust zone, untrust zone,  DMZ and user-define DMZ. Now, our requirement is to configure it for HA Active/Active. I read on the technical files on the internet that for us to obtain or goal, we should have atleast 1 dedicated port for HA. My questions are:

1. Is it possible for us to set up the 2 x SSG 320 for HA even without a dedicated port?

2. In case this will be possible, what are the drawbacks/disadvantages/implications/issues that may arise for this set up?

Set up is below

R1==>untrust[FW1]trust===>[switch]<==trust[FW2]untrust<===R2

=] between R1 and R1 we're running VRRP
=] switch is Cisco 2900 series w/ 4 VLANs


Please advise and many thanks.

Lily
Logged
signal15
Administrator
Sr. Member
*****
Posts: 480


View Profile WWW
« Reply #1 on: September 30, 2009, 01:12:47 AM »

No, you need a dedicated port.  You can free up a port by doing a trunk from your switches to the firewall and then using 802.1q tagging on subinterfaces.

Why are you doing active/active?  If you exceed 50% capacity on the firewalls, and one dies, you are down.  You no longer would have redundancy.  Plus, the increased complexity is not worth it.  More chance for configuration errors both on the firewall and the surrounding network equipment that could take it down, and more chance of problems.  Troubleshooting is going to take you longer also if there is a problem. 

Active/passive is a more solid solution.  I've done a lot of both.  Most customers that insist on active/active change their minds either during implementation or shortly thereafter.  Juniper also recommends active/passive.
Logged
buntit
Newbie
*
Posts: 2


View Profile
« Reply #2 on: October 01, 2009, 07:47:36 PM »

Hi Signal! Appreciate the reply from you. I do have additional question if you don't mind regarding your reply below:

[No, you need a dedicated port.  You can free up a port by doing a trunk from your switches to the firewall and then using 802.1q tagging on subinterfaces.]

=] Where will I put the current IP address of that interface that I need to free up and be used for HA?
=] If I my understanding is correct [which you can correct if I am wrong], you want me to do the set up below, right?

[FW1]<==dedicated port==>[switch1 w/ vlan]<== trunk connection==>[switch2 w/ vlan]<==dedicated port==>[FW2]

=] if the one above will be my set up, I have to configure my trunk port to allow the vlan I configured for the dedicated port connection of my FW right?
=] as for the A/A set up, I agree with you on it. So the set up will be the A/P. Just bothered now where will I put the IP address of the existing port on the FW that I'll be needing to free up to become a dedicated port for HA.

Many thanks.

Lily=]

Logged
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 39593
  • Total Topics: 10459
  • Online Today: 72
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 1
Guests: 31
Total: 32
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.203 seconds with 37 queries.