Skip to main content
akabarasif
New Member
July 31, 2020
Question

How to Config redundant ISP with HA without having switch?

  • July 31, 2020
  • 3 replies
  • 5314 views

HI,

we have 2 ISPs directly connected. it is P2P link one is L3-P2P another is L2-P2P, 1 link is connected to primary firewall and 2nd is connected to secondary firewall, both firewall has active/active HA enabled. how can i utilised both ISPs 50/50%. Stacked core switch is connected to both firewall.

    3 replies

    lobstercreed
    New Member
    July 31, 2020

    Can you not buy a couple of tiny cheap unmanaged switches?  If you're going to do HA you need to do it right which means you're going to need a switch.

     

    If you don't want to buy anything, create two VLANs for this purpose on your core switch.  It does consume 6 total ports, but that's what we have done.  VLAN 3333 is ISP1 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.  Then VLAN 3334 is ISP2 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.

    akabarasif
    New Member
    August 16, 2020

    lobstercreed wrote:

    Can you not buy a couple of tiny cheap unmanaged switches?  If you're going to do HA you need to do it right which means you're going to need a switch.

     

    If you don't want to buy anything, create two VLANs for this purpose on your core switch.  It does consume 6 total ports, but that's what we have done.  VLAN 3333 is ISP1 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.  Then VLAN 3334 is ISP2 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.

    Hi,

    actually we are using same firewall instead of both firewall without HA for a time being. we config the SD-wan with ipsec tunnel but link is not fully utilising. each link has 2 Mbps speed. both side we config sd-wan from HQ-branch and branch-HQ. but i see more packet loss in 1 link. could you please tell me how to solve this issue ?

     

    harmesh88
    New Member
    August 24, 2020

    As you mentioned in post that you dont have switch for ISP Connectivity 

     

    You should connect both ISP in Primary Firewall and then you can use ISP load sharing Method and use both ISP 

     

    Once your primary Firewall will goes down you should manually connect both link to secondary Firewall

     

    If you dont want manual fail over and need auto fail over - You should have one L2 switch other wise you can use port from your core switch by making one isolated VLAN .

     

    And you can achieve it 

     

    Regards,

    Harmesh Yadav

    CCNP CCSE

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!