SSL VPN
Reply
Contributor
ralvez
Posts: 48
Registered: ‎01-28-2011
0
Accepted Solution

SA HA cluster: ¿can I put the management interfaces on different subnets?

Hello team:

¿Is it possible to configure the management interfaces of the members of a SA cluster on different subnets? I know this is not possible with the internal or the external interfaces (both internal interfaces must belong to the same subnet, and both external interfaces must belong to the same subnet as well), but I am not sure whether I must follow this on the management interfaces.

And the customer would like to have each management interface on different subnets.

 

Your comments will be greatly appreciated

Rogelio Alvez

Argentina

Moderator
SHKM
Posts: 122
Registered: ‎03-13-2008
0

Re: SA HA cluster: ¿can I put the management interfaces on different subnets?

Hi Ralvez,

 

         Are you talking about Active/Active cluster or Active/Passive cluster?

 

Thanks,

Suresh

Moderator
SHKM
Posts: 122
Registered: ‎03-13-2008

Re: SA HA cluster: ¿can I put the management interfaces on different subnets?

Hi Ralvez,

 

     In a quick lab test and KB reserach gave me following results   

 

Active/Active : Management ports can be in different subnet

Active/Passive: Management port must be in same subnet but different ip.

 

Refer: http://kb.juniper.net/InfoCenter/index?page=content&id=KB21815

 

Thanks,

Suresh

Contributor
ralvez
Posts: 48
Registered: ‎01-28-2011
0

Re: SA HA cluster: ¿can I put the management interfaces on different subnets?

Hi Suresh: A/P

 

I was told that in this configuration both interfaces must belong to the same subnet.

 

Thank you very much for your kind answer!

regards, Rogelio

Contributor
ralvez
Posts: 48
Registered: ‎01-28-2011
0

Re: SA HA cluster: ¿can I put the management interfaces on different subnets?

Hi Suresh!

It was you the person who answered :smileysurprised:)

 

Thank you so much.

Rogelio

Moderator
SHKM
Posts: 122
Registered: ‎03-13-2008
0

Re: SA HA cluster: ¿can I put the management interfaces on different subnets?

You're welcome Rogelio..! 

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.