I need help in configuring chassis cluster on a SRX340 device. Would be greatly appreciated if someone can suggest.
Currently, a SRX340 is running in a production environment. Now I need to add another SRX and perform the clustering. What are the best steps:
- Configure the standby SRX with the cluster and node id and connect to running/active SRX and reboot? Will this procedure receive the config from a running/active SRX?
- Configure the standby SRX with cluster and node id, copy the config from a running SRX, paste into the standby SRX and connect together. Does this procedure require the reboot?
Out of above two which one is the recommended choice OR what are the best steps that juniper recommends for adding the standby device (in this case SRX) and perform the clustering?
Also for SRX340, are there any specific ports that I need to connect the cables for control and fabric (data) links? I know for the data link, GE port is good but not sure about whether the SRX340 has a specific GE port assigned for fabric (data) link.
So basically, there would be failover testing between node 0 and node 1. First, node 1 becomes primary when I take it to live in the network and then node 0 after reboot, right?
Would it be possible in reverse order? I mean, leave the node 0 as it is. Connects the node 1 (assume already prepared the configuration on node 1 for a cluster) to node 0, reboot and once a cluster established, disable the interface on node 0. In this way node 1 becomes primary and vice-versa.
[CP] :- So basically, there would be failover testing between node 0 and node 1. First, node 1 becomes primary when I take it to live in the network and then node 0 after reboot, right?
[Juniper] :- Yes your understanding here is correct.
[CP] :- Would it be possible in reverse order? I mean, leave the node 0 as it is. Connects the node 1 (assume already prepared the configuration on node 1 for a cluster) to node 0, reboot and once a cluster established, disable the interface on node 0. In this way node 1 becomes primary and vice-versa.
[Juniper] :- No, not possible other way round, unless you are fine for a traffic disruption. [Methodology I reverted with is written towards minimal downtime]
Reason :- Since node0 is the present running standalone.
It would require cluster config and a reboot to become node0.
Hence, New member can be made in cluster with cluster config etc and be ready to take and server traffic.
Upon traffic cutover from one Standalone to new Node1, standalone can be worked upon for the chassis cluster makeover.
Once standalone is ready as a node0 pair, steps as defined in my last update can be followed to make it part of cluster pair.
Note: I have called the new node as Node1 for an understanding viewpoint and the already existing as future node0. Who will be 0/1 is your wish.
I hope this clarifies the remaining doubts. Do revert for any further clarifications.
I have followed the below steps and it performed the clustering:
-set chassis cluster cluster-id and node id reboot (node 1)
- Once the firewall (node 1) booted and back up, replaced the config on the firewall (node 1) with the one on the node 0 (currently active) firewall, After this, shut down the firewall (node 1) and taken it to the site. - At the site, mounted the firewall, leave it powered off. Then connected the HA cables, Port 1 of node 0 to port 1 of node 1. Port 2 of node 0 to Port 2 of node 1 - And then powered on node 1
It performed the clustering without rebooting however, I haven't gone through the failover process as you mentioned. It's important to do the failover testing but due to time constraint, I have planned for the next time.
Your comments and previous post really useful and contains all process from clustering to the failover test. It definitely helps me.