Solved

dual PIX 515e / Catalyst 3750 / Dell server - high availability

Posted on 2006-10-31
6
512 Views
Last Modified: 2013-11-16
Hi everyone,
I need to setup a small network with high availability in mind.

We have following network equipment:
- two Cisco PIX 515e firewalls
- two Cisco Catalyst 3750 switches
- two Dell servers with two NICs each (Intel/Netgear but can work in a team using Intel ANS)

What is the best way to configure this network?

Is it possible to configure it so that system can still work if eg. following components fail: NIC1, switch1 and pix2?

Thanks
0
Comment
Question by:milan_novkovic
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 27

Accepted Solution

by:
pseudocyber earned 500 total points
ID: 17841190
Pix                      Pix
 |                        |
---VRRP or GLBP---
 |                        |
 |                        |
3750=======3750
 | \                  /  |
 |  \                /   |
 |    \             /    |
 |      \         /      |
 |        \     /        |
 |          \  /         |
 |          / \          |
 |         /    \        |
 |       /        \      |
 |     /            \    |
 |   /                \  |
 | /                    \|
Dell                    Dell
Teamed             Teamed

If you're using multiple vlans, then trunk your vlan across on both switches.  Make two connections between switches and aggregate them (Fast Etherchannel) for redundant load balancing connections.

VRRP or GLBP will provide firewall redundancy in case one fails.  GLBP is active/active.

Team the NICs on your Dells.  Then, connect one cable from each switch to the Dells.  Aggregate the two connections if you can on the switch side and if so, then use Switch Assisted Load Balancing (SLB) (naming changes).  If you can't aggregate the two connections (bond, or Etherchannel) then use Fault Tolerant Load Balancing (FTLB) on the Server Teaming end.

HTH
0
 

Author Comment

by:milan_novkovic
ID: 17843341
I forgot to mention that PIXes have active/standby licences, so standby would work only when active fails.

We received Stackwise cable with 3750 switches. Is there a need to use switch stacks for our needs or should switches be connected using only ethernet cables?
0
 
LVL 27

Expert Comment

by:pseudocyber
ID: 17843359
I would use the stacking cables.  Faster, and don't burn Ethernet ports.
0
Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!

 

Author Comment

by:milan_novkovic
ID: 17849961
Is there a way of configuring this network so that system would work if eg. PIX1 and Switch2 fail (PIX1 is connected to Switch1) ?
0
 
LVL 27

Expert Comment

by:pseudocyber
ID: 17850112
Not without connecting both pixes to both 3750's.
0
 

Author Comment

by:milan_novkovic
ID: 17857814
How can I connect both pixes to both catalysts? I think it's not possible to use the same subnet for two different interfaces on PIX 515e.
0

Featured Post

Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question