2 Firewalls with 2 switches and one PUBLIC IP

Started by lmgmelim, September 08, 2024, 11:53:43 PM

Previous topic - Next topic
hey

We want to put 2 OPENSENSE firewalls woking with High Avaibaility (same public IP.). Behind, we have 2 switches (2 SPINE Switches).

From my understanting, OPENSENSE HA works as Active\Master (not a CLUSTER), but my 2 SPINE switches work as ACTIVE\ACTIVE

Can i connect the first switch directly do the first OPENSENSE and the second switch to the second OPENSENSE? it wiil work since theres is only one ACTIVE NODE on the firewall side? What is the best way to connect 2 firewalls and 2 switches in my scenario?

Can the switches do MLAG aka multi chassis LACP aka "stacking"? In that case connect each OPNsense to both switches with a LAGG interface and if you need to further separate internal networks use VLANs on top of that.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)