Basic HA Network design help

Posted on 2009-02-15
Last Modified: 2012-08-13
I need some help with regards to the best way to design my network. I've supported a similar setup before, but wasn't involved with the initial design of it.

Equipment list;

2 x 550e Watchguards,
2 x HP Procurve 24 port switches,
3 servers (initially),
30 external IP addresses.

My aim is to create an HA network that would allow for either one of the switches or firewalls to fail without causing downtime. I have setup teaming on the servers, so that both NICs share the same IP and one NIC from each server will be to connected to each of the switches. I intend to put these 3 servers on different VLANs for security and future expansion reasons. .

I shall setup 3 VLANs,  101, 102 and 103 on the HP Procurves, with one server in each (www, sql and email). I understand that I need to setup a heartbeat between the two firewalls and that I need to have a connection from both firewalls, trusted interface to switch, and the optional interface to the other switch.

Do I need to use VRRP? This is something I remember seeing from the old setup, but I'm rather wet behind the ears with all this, sorry.

A diagram with some example IP's and wiring etc would be greatly appreciated.
Question by:jammy-d0dger
    LVL 10

    Accepted Solution

    You'll need 3500/5400 series 24 port switches with the Premium License to use VRRP.

    LVL 32

    Assisted Solution

    You would be better off connecting a cross-over cable between the units for heartbeat; hub is recommended if you do not wish to cross-over cable as most switches block heartbeats which are more like ARP frames.

    Please note you need to have license with newer WG software to configure HA.

    Please let know if you need any specific details for configuring HA.

    Thank you.

    Featured Post

    Courses: Start Training Online With Pros, Today

    Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

    Join & Write a Comment

    Suggested Solutions

    Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
    Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now