Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Dedicated Management Port (not MGMT) + Peer Administration link

Hi there,

we are just implementing a management vlan in our network. Therefore I added the mgmt-vlan on one of our 2 main-connections to the coreswitch. Management of switches and servers is working properly.

Last step would be to manage our XGS active-passive cluster itself over the management vlan. I would like to combine it with the cluster option Peer administraion link where I can access the auxilary device. I'm aware of this option doesn't accept vlan-interfaces.

Currently I have configured:

  • Main-connection to coreswitch:
    XGS > Coreswitch
    Physical interface: Dummy-address 192.168.x.x
    VLAN-interface: Mgmt-vlan 10.1.10.x
  • XGS-Port#6
    XGS > dedicated MGMT-Switch (connected with coreswitch)
    Physical interface #6: address 10.1.10.10
  • Cluster-Config
    Peer administration link: 10.1.10.11

I chose Port#6 as dedicated Mgmt-port not the built-in port MGMT because I read that port MGMT on auxilary device uses the IP of the primary device.

Direct access to 10.1.10.11 is possible. Routed access is not possible, I can see IP-spoof in the logs.

I'm a little bit lost here and kindly ask for some ideas! I'm looking for a clean configuration.

Currently I see the only possibility to move the Mgmt-vlan to Port#6 and create a additional connection to the coreswitch - but is it possible then to configure address 10.1.10.10 on top on the physical interface?

Thanks in advance!

Christian



This thread was automatically locked due to age.