Hi CheckMates
We're currently running a clustered Firewall (4800, R80.20) with three connected 1G-interfaces
- External (eth1): Vlan-Trunk, 1 Vlan
- Internal (eth2), Vlan-Trunk, 8 Vlans
- Sync (eth3), Access-Port
The Firewalls were now upgraded with a 2x10G-Module (eth1-01, eth1-02) each. I will create a LACP-bond (2x10G) and would like to move all Vlans from the External- and Internal Interfaces to the new 10G-Bond. The Sync-Traffic will remain on the separate 1G-Interface for now.
My next steps would be:
- Create the new LACP-Bond (bond1) on both members and make sure it is UP
- Standby-Node: Remove first Vlan-Interface (e.g. eth2.32) including IP-configuration in Web-UI
- Standby-Node: Create new Vlan-Interface (e.g. bond1.32) on 10G-Bond with IP-address in Web-UI
- Magic in SmartConsole and Policy Push *
- Failover
- Repeat Steps 2-4
- Now repeat steps 1-6 for every Vlan or maybe do all in one run
* Now the part where i'm struggling..
- Should i now get the new topology of that cluster-interface (Int.32) in SmartConsole?
- Or rather update the Interface-Name by hand? (see screenshot below)
- Is it even possible to configure a VIP over two different ports for a short time (member1: eth2.32, member2: bond1.32)
Or is there another better and easier way? It wouldn't be a problem to announce a small downtime.
Thanks and regards
Christian