Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Cluster of SRX Firewalls in Two Data Centres

$
0
0

Hi,

 

You cannot use Internet to connect the HA Control and Fab links between the two SRX nodes because of the following reasons :-

 

  1. Latency needs to be less than 100ms.
  2. For HE, minimum bandwidth needed is 1Gbps, for Branch, this varies.
  3. The network should be isolated from any other hosts.
  4. The network connecting both the nodes should be free of any traffic.
  5. The communication between the devices uses private MAC and IP addresses, which could conflict with other hosts and would not be routable on the internet.
  6. IGMP snooping should be disabled on the L2 device.
  7. The L2 device should not perform IP Legitimate check.
  8. Jumbo frames should be allowed to pass through.
  9. Control and Fab links should be in separate Vlans.

 

All the above requirements cannot be achieved traversing through the internet.

Hence it is not possible to deploy a chassis cluster with control and fab links traversing over the Internet.

 

Regards,

Sahil Sharma

---------------------------------------------------

Please mark my solution as accepted if it helped, Kudos are appreciated as well.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>