Hey guys,
I'd like to ask you for help regarding a redundant network uplink from our Sophos SG 230 A/P Cluster to two stacked Netgear M4300 Switches.
Here's our setup:
As you can see, we installed two Flexiport-modules with 10G Fibre Modules in our Sophos SG 230 Firewalls. We'd like to uplink those to our newly bought Netgear M4300 Switches, that are connected by a stacking cable (DAC). This uplink needs to be a redundant VLAN-Trunk.
In Sophos UTM, I created a Link aggregation group over both Fibre-Modules (eth6 and eth7 in our case).
Now, in the Netgear Switch, I have different possibilities to configure the uplink ports:
- keep them "stupid", just setup a VLAN-Trunk over all 4 ports individually
- configure 2 LAGs over interfaces 0/1 and 1/2 (top row) and 0/2 and 1/2 (bottom row) and use these LAGs for the VLAN trunks
If we'd go for the second option, there are some configuration options we have for our Netgear switches, as can be seen on the next image.
We tried the second option first (LAG on both sides with different options set in our Netgear Switches), which did not work very well. Currently we do some testing with the first option (normal VLAN trunks and no LAG on Netgear side), which seems to work better.
For testing, we ping the Management VLAN of our Netgear Switch and:
- disconnect the LWL cables from our Master Sophos UTM one after another - ping should continue --> works as expected
- power done one Netgear switch in our stack - ping should continue --> works for the Slave-Switch, not as we power down the master switch
Strange thing is: as soon as we power down the master switch, all ping packets are lost, however, the management interface is still available...
So, our config still does not seem "bulletproof", so I'd like to hear your opinion on our setup. Maybe, anyone in the Forum has a similar setup and can help us find the "best" setup.
Thanks a lot in advance!
Best regards
Sascha
This thread was automatically locked due to age.