Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Antonio_Martins
Contributor
Jump to solution

Bridge & routing in the same gateway

Hi mates,

I need your clarification for the following scenario:

Some time ago, we had to configure two interfaces in bridge mode in ClusterXL running in HA mode so we could filter traffic between servers in different buildings (Main and DR) that communicate through a layer 2 circuit.

Now we want to use the same gateway to route traffic from the DR building using the same gateway but it doesn't work.

I've made this drawing to better explain what is happening:

In the main site, the Blue Servers can communicate with the Red Servers.

The Blue Servers in DR site can communicate with the Blue Servers in the main site.

The Blue Servers in DR site can't communicate with the Red Servers in the main site.

In the admin guide I've found the sentence 'The Security Gateway cannot filter or transmit packets on a bridge interface that is inspected before (double-inspection)'.

Does this mean that it's not possible to achieve what we want?

0 Kudos
2 Solutions

Accepted Solutions
Maarten_Sjouw
Champion
Champion

This could very well be the limitation. There is one way to resolve that issue and that would be by turning on VSX and setup the cluster as a VSX cluster. In VS0 you would handle the Bridge interfaces and then you create a VS1 to control the traffic to the Red zone. Second advantage for this method would be that you can run VS0 active on unit 1 and run VS1 on unit 2.

Regards, Maarten

View solution in original post

PhoneBoy
Admin
Admin

That is exactly the limitation.

VSX, as Maarten says, is the way to achieve this.

View solution in original post

2 Replies
Maarten_Sjouw
Champion
Champion

This could very well be the limitation. There is one way to resolve that issue and that would be by turning on VSX and setup the cluster as a VSX cluster. In VS0 you would handle the Bridge interfaces and then you create a VS1 to control the traffic to the Red zone. Second advantage for this method would be that you can run VS0 active on unit 1 and run VS1 on unit 2.

Regards, Maarten
PhoneBoy
Admin
Admin

That is exactly the limitation.

VSX, as Maarten says, is the way to achieve this.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events