Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
marcinw
Contributor
Jump to solution

High Availability (active/standby) and NAT on Gaia

Hi 

We think about migration from one FW to two FWs in active/ standby mode. Requirement regarding physical interfaces are clear , each physical interface requires 3 IPS (2 on each FW and 1 Virtual) , but what about IPs with static NAT and public services? For example we have set up our mail server  with external IP 1.1.1.1/24 (not physical interface) , does it mean that we will have to allocate also additional IPs 1.1.1.2 and 1.1.1.3 for HA ?

 

thanks

0 Kudos
1 Solution

Accepted Solutions
BikeMan
Contributor

so it is not required allocating additional 2 IPs for external logical IPs: correct

the same NAT table is kept by 2 firewalls regardless of NAT direction inside-outside or outside-inside and virtual addresses are not needed : yes

We should allocate additional IPs to physical interfaces/subinterfaces : no

 

You only have to check proxy arp config : if any, must be the same on both cluster's member.

Then push policy. 

 

View solution in original post

4 Replies
Chris_Atkinson
Employee Employee
Employee

NAT IPs are per cluster not per node.

CCSM R77/R80/ELITE
0 Kudos
marcinw
Contributor

thank you for response, so it is not required allocating additional 2 IPs for external logical IPs, it's just the same principle of working , the same NAT table is kept by 2 firewalls regardless of NAT direction inside-outside or outside-inside and virtual addresses are not needed  ? We should allocate additional IPs to physical interfaces/subinterfaces ?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

ClusterXL itself doesn't change the number of IPs needed for NAT

CCSM R77/R80/ELITE
0 Kudos
BikeMan
Contributor

so it is not required allocating additional 2 IPs for external logical IPs: correct

the same NAT table is kept by 2 firewalls regardless of NAT direction inside-outside or outside-inside and virtual addresses are not needed : yes

We should allocate additional IPs to physical interfaces/subinterfaces : no

 

You only have to check proxy arp config : if any, must be the same on both cluster's member.

Then push policy. 

 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events