SRX

last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  question about chassis cluster active and passive group

    Posted 11-25-2015 15:27

    FW.png

    here is the topology  . my quesitions are 

     

    1. if traffic  that  arrives in  Router B wants to acess server behind the FW . and the next hop is  the FW . how doesn the traffic go?. it is Router B - L2 switch 2 - FW - L2 switch 3 or Router B ->L2 switch 2 ->L2-switch 1->FW->L2 switch 3 .

    if the link between L2 switch 1 and 2 is down . traffic from Router B will can acess the server behind the FW ?

    2.if the link between server and L2 switch is down .  traffic that arrives in Router A and Router B will not be able to acces the server behind the FW ?



  • 2.  RE: question about chassis cluster active and passive group

    Posted 11-26-2015 01:37

    Hi,

     

    It all depends which SRX is primary at the time the traffic arrives.  In your diagram, Node0 is primary and Reth0 and Reth1 are also primary on this device so traffic flow is as follows:

     

    Router B -> L2 Switch 2 -> L2 Switch1 -> Fw Node 0 (Reth1) -> L2 Switch 3 -> Server

     

    IF the link between L2 Switch 1 and 2 is down, Reth1 should failover to Node 1(provided weight etc is configured accordingly) and traffic would flow like so:

     

    Router B -> L2 Switch 2 - > FW

     

    Im not sure how your server is set up but if say the link to L2 Switch 3 fails, then yes, the server will be inaccessible.  If your switches were in a Stack or Virtual chassis with the server NICs in a HA config (team for example), then you would have no issues.

     

    You could also look into Upstream Device Failure Detection.



  • 3.  RE: question about chassis cluster active and passive group

    Posted 11-26-2015 02:24

    thank you for your answer .  why reth1 would   failover to Node 1. i think even weight is configured, FW can only detect reth0 and reth1 state , and failover according the confiugred weight. could the FW detect link down between L2 switch 1 and 2 ?



  • 4.  RE: question about chassis cluster active and passive group
    Best Answer

    Posted 11-26-2015 02:41

    Sorry about that, I wrote that as if a switch had failed and not the actual link. 

     

    What I suggest is that you configure redundant links between the front facing switches.  This way would yould have to lose multiple links in order to fail entirely.  If this happens, one would assume the switch is dead and the Reth will then failover.