Configure an NGFW cluster of two firewalls for node redundancy.
| Where Can I Use This? | What Do I Need? |
|
|
For Strata Cloud
Manager managed NGFWs:
One of the following for Panorama managed NGFWs:
|
Before you configure the firewalls to an NGFW cluster, perform the following
prerequisites:
The steps in the example task to configure an NGFW cluster are based on this topology
example of two MC-LAGs. The orange links connected to Node 1 and Node 2 on the
client side belong to AE1 (an MC-LAG). The orange links connected to Node 1 and Node
2 on the server side belong to AE2 (another MC-LAG). Traffic from the client at
10.1.7.100 goes to the switch and is then divided between the two ingress AE1
interfaces and then egresses the two AE2 interfaces to the switch, and then goes
over the orange link to the server at 10.1.8.200.
The gray links connected Node 1 and Node 2 are orphan ports. Traffic from the client
at 10.1.1.100 goes to the switch, to Node 1, across an HSCI interface to Node 2,
egresses Node 2 to the switch, and then to the server at 10.1.2.100.