Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LAG configuration

Hello,

So I have a weird scenario and I need second opinion.

We have two firewalls Active Passive and two switched Active Active

The first switch was configured to connect to the primary firewall on a port F4 and this port has vlan on it,

The second switch was configured to connect to the secondary firewall same port. So however configured this setting was only thinking of a failover only for firewalls not switches. So in this scenario if the first switch fails the second will not rout traffic as it is conectted to the secondary passive firewall.

To solve this i have to create a LAG port for the two ports and connect the second switch two. However since the first port has vlans on it I cannot add it to the group, I have to remove the vlans and recreate them on the LAG.

What is the best practice in this scenario to avoid any downtime, misconfigurations, or recreating firewall rules?



This thread was automatically locked due to age.
  • Unfortunately, there is no simple way, as you can't add a configured port to a LAG or move a VLAN from one port to the other.
    You have to rebuild interface and VLAN's.
    You may export the interface-config, edit the XML and reimport ... may need less time for transition.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • There will be a option to do this in V20.0 MR2. 
    This released is coming up soon and will give the option to move interfaces by using Backup / Restore. 

    __________________________________________________________________________________________________________________