CARP and Multiple Switches
-
I'm trying to eliminate the possibility of a switch failure and put one firewall on switch a and firewall b on switch b. The 2 units have a sync interface and there is some connectivity between the switches on some vlans. I do not have it setup so that the 2 firewalls can talk to each other on the multiple wan interfaces. When I do this CARP makes both machines appear as masters. Do the firewalls need to be on the same switches in order for CARP to work on these multiple wan interfaces correctly?
Andy
-
CARP needs to be able to talk to the other node on every CARP interface. You need to make sure the WAN interfaces of each firewall can communicate with each other. (same for other interfaces with CARP)
-
this makes me wonder, how could you elimate the posability of a switch failure having only one switch between your lan interface on the firewall and lan?
-
Well what I ended up doing was putting each firewall in it's own switch and passing a common vlan between the switches. Then since I have multiple internet connections I have put one of those in a different vlan on one switch and it goes to both switches with the firewalls wan interface picking up that vlan. Then I take the other connection and put it in the other switch with a different vlan. I have gone one step further and plugged both wan connections into each switch and disabled the port so I don't have a loop. This way if I lose a switch I can still get to the network and just enable the port so the other wan connection will pick up.
I thought that carp would pass status through the sync interface but it does not, that would make the solution much each to eliminate switch failures.
Andy
-
I'm feel for you here. You are doing the right thing..
I did the same (put two switched on the private (lan) side to avoid a single point of failure). But I did not have any CARP problems. I was under the impression that the carp traffic was through the synch link… At least for me..
-
I'm feel for you here. You are doing the right thing..
I did the same (put two switched on the private (lan) side to avoid a single point of failure). But I did not have any CARP problems. I was under the impression that the carp traffic was through the synch link… At least for me..
Do you have your incoming WAN links setup this way or just the lan side?
Andy