CN-Series HSF Architecture
Table of Contents
11.0
Expand all | Collapse all
-
- CN-Series Key Concepts
- CN-Series Core Building Blocks
- Components Required to Secure Kubernetes Clusters with CN-Series Firewall
- CN-Series Deployment—Supported Environments
- CN-Series System Requirements
- Quickstart- CN-Series Firewall Deployment
- CN-Series Performance and Scaling
- Additional CN-Series Resources
-
- CN-Series Deployment Checklist
- CN-Series Prerequisites
- Install a Device Certificate on the CN-Series Firewall
- Create Service Accounts for Cluster Authentication
- Install the Kubernetes Plugin and Set up Panorama for CN-Series
- Get the Images and Files for the CN-Series Deployment
- Editable Parameters in CN-Series Deployment YAML Files
- Enable Horizontal Pod Autoscaling on the CN-Series
- Secure 5G With the CN-Series Firewall
- Enable Inspection of Tagged VLAN Traffic
- Enable IPVLAN
- Uninstall the Kubernetes Plugin on Panorama
- Features Not Supported on the CN-Series
-
- CN-Series HSF System Requirements
- Configure Traffic Flow Towards CN-Series HSF
- Test Case: Layer 3 BFD Based CN-GW Failure Handling
- View CN-Series HSF Summary and Monitoring
- Validating the CN-Series HSF Deployment
- Custom Metric Based HPA Using KEDA in EKS Environments
- Features Not Supported on the CN-Series
CN-Series HSF Architecture
The CN-series HSF cluster consists of
a pool of CN-MGMT (management), CN-NGFW (dataplane), CN-GW (gateway)
and CN-DB (database) pods connected by internal networks. The CN-MGMT
pods provide the cluster management plane functionality The CN-NGFW
pods provide the cluster data plane security functionality. The
CN-GW pods are the entry point into the cluster and distribute traffic
between the CN-NGFW pods. The CN-DB pods provide the central cluster
session cache used by the CN-NGFW pods.

The CN-Series HSF supports two CN-MGMT containers that provide redundancy and availability.
However, only one of the two CN-MGMT containers can take connections from CN-NGFW DPs.
The connected CN-MGMT will run as a StatefulSet service to allow CN-NGFWs to connect
only to the active CN-MGMT. The other CN-MGMT container will not connect to CN-NGFW
containers unless the current CN-MGMT fails.
