Hi,
We have 2 sites connected by a 10Gb circuit. We have a pair of Firewalls running R80.30 set as Active/Standby using ClusterXL.
We have an eBGP peering to a remote entity which uses the Cluster VIP on our side.
The problem, as noted yesterday during a downtime window for one of the sites, is that if we take a site down for maintenance the FWs stop talking to each other so they switch the Standby FW to Active and it takes over the VIP. However this site was the one we had taken down therefore the whole company lost connection to the remote entity.
I read that it is best practice to use the VIP for ClusterXL and BGP but is that only really the case when both FWs are in the same rack?
If they are in different sites would it make more sense to have 2 eBGP peerings and an iBGP peering between them?
Is there going to be any problem with setting this up, due to them being essentially the same cluster?
Will this work?