hi @yeruel
This is a very interesting design. ElasticXL is still a relatively new technology, and honestly, I have never deployed ElasticXL in production, especially in a topology like this. However, based on my experience with Check Point, the documentation, and some research, I'll try to help. I also think this would be a great case to document and share back with the community once implemented.
My first concern is the proposed topology. I would not recommend connecting the ElasticXL Security Group (or any Check Point firewall) directly to the Palo Alto Active/Active pair using cross-connected LACP as shown. Firewalls are Layer 3 devices, not switches, and should not be expected to provide MC-LAG functionality or advanced switching functionalities. I would recommend that you introduce a redundant switch pair between both platforms (CheckPoint and Palo Alto) and perform Layer 3 routing between the firewalls.
My thoughts on your questions:
- Routing design: Layer 3 transit networks through a redundant switch pair.
- Dynamic routing: Yes, I would recommend it.
- eBGP or OSPF? I would lean toward eBGP because it provides better routing policy and control between two different firewall platforms.
- Peering model: I would configure routing using the logical ElasticXL interfaces rather than treating each physical member as an independent router.
- LACP: Yes, but only with a single logical LACP peer. Based on the proposed topology, I would not build a single LACP bundle across both Palo Alto firewalls.
- Static routing: It can work, but it does not solve the Layer 2/LACP design concern.
- Asymmetric routing: Start with a preferred path and validate failover first. Consider ECMP/load sharing only after the design is stable.
Finally, because this is a cross-vendor architecture involving a relatively new platform like ElasticXL, my recommendation would be to engage your Check Point Account Manager and request assistance from Professional Services. They can validate the design, confirm what is officially supported, and help with the implementation if needed. I would recommend doing the same with the Palo Alto team.
Good luck, and please come back and share the final design. I think many people in the community would benefit from seeing a real-world ElasticXL deployment like this.
Good links to review:
R82 ScalablePlatforms admin guide > ElasticXL
https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Conte...
ElasticXL supported combinations of hardware platforms in R82 and higher
https://support.checkpoint.com/results/sk/sk183513
R82 Gaia Advanced Routing Administration Guide
https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_Advanced_Routing_AdminGuide/C...