Dear Team,
Hello,
We are implementing ClusterXL and Management High Availability.
We have also activated Anti-Spoofing.
A diagram of the network infrastructure is displayed below.
Under these conditions, the Security Gateway is dropping the following packets:
i1&i2 -> Management NW network address (4th octet 0), UDP/8116
i1&i2 -> 239.255.255.250, UDP/1900
m3&m4 -> m1&m2, TCP/45112 TCP/53393
The cluster configuration appears to be functioning correctly, as indicated by SmartConsole or the output of the "show cluster state" command.
It is effectively executing failover procedures even after simulating failures, such as shutting down the active SG.
(Question 1) Is there an issue with this current setup?
(Question 2) If there is an issue, what steps should be taken to resolve it (e.g. implementing additional firewall policies)?