Interconnect Links
Where Can I Use This? | What Do I Need? |
- CN-Series HSF Firewall deployment
|
- CN-Series 11.0.x or above Container Images
- Panorama running PAN-OS 11.0.x or above version
|
All the CN-GW, CN-DB, and CN-NGFW pods
will be connected to each other via the Cluster Interconnect (CI)
link which is a multus interface. The CI link is a data port reserved
for cluster communication and forwarding packets between cluster
members. Ethernet x/1 is used for the CI links on all relevant pods.
The CI link can also be used to forward traffic from one CN-NGFW
to another.
The CN-GW and CN-NGFW pods are connected to each other via Traffic
Interconnect (TI) link which is a multus interface. The TI link
is a data port reserved for internal traffic within the cluster.
Ethernet x/2 is used for the TI links on all relevant pods.
On the CN-GW pods Ethernet x/3 onwards will be used as external
interfaces connecting to the customer network.
CN-Series HSF supports only IPv4 protocol.
For on-premises environment, a DHCP server or IPAM is needed to
assign IP addresses to the CI and TI interfaces. For AWS EKS, the DHCP server is part of
the underlying infrastructure. Hence, IP addresses are assigned automatically to the CI
and TI interfaces in cloud environments.