Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: SRX routing with redundant connections

$
0
0

Let's clarify, web traffic = TCP = stateful.

 

Without HA cluster this becomes, in my opinion, an exceedingly complicated setup.

 

  1. You need to configure something like VRRP so that both SRX devices can appear as a single "default gateway" to the rest of the network.
  2. You need to connect the two SRX boxes together. Then from the point of view of SRX1 the two ISPs become ISP1 and SRX2. And, from the point of view of SRX2, the two ISPs become SRX1 and ISP2.
  3. Use ECMP routing to split the traffic (http://www.juniper.net/documentation/en_US/junos14.1/topics/usage-guidelines/policy-configuring-per-flow-load-balancing-based-on-hash-values.html). The config in there says "per-packet" but that's a misnomer: it's not really per-packet.

Per your diagram, failure of an SRX box would effectively mean a failure of the corresponding ISP.

 

All this complexity can be significantly reduced by placing the firewalls in a cluster. (While also introducing the complexity of setting up a cluster ... because that always goes without any issues... Smiley Indifferent )


Viewing all articles
Browse latest Browse all 17645

Trending Articles