We have 2 Spark 1595 appliance R81.10.08 in local management that forms a simple HA cluster with following topology:
WAN: VIP 202.175.116.210/30, Primary member: 192.168.100.1, Secondary member: 192.168.100.2
(Since ISP only provide 1 public IP, the Cluster VIP is cross different subnets as this feature is now supported in version R81.10.X)
LAN1: VIP 192.168.1.1, Primary member: 192.168.1.253, Secondary member: 192.168.1.254
LAN2 (Sync): 10.231.149.1 and 10.231.149.2
The Switch Ports 27, 28 and 29 formed an isolated VLAN in access mode, and connect to the two WAN ports on Firewall A and B and ISP router.
We found there is 3-4% PING packet lost when sending 1000 PING packet from Firewall to 8.8.8.8 if the firewall is in HA mode. But no PING lost if the firewall is in standalone with the same connection.
Could anyone suggest what is the best practice or requirements on switch ports for Cluster VIP connections? Thanks.