OSPF in HA
- March 15, 2016
- 1 reply
- 11888 views
We were hoping to leverage the OSPF capabilities between our Cisco Nexus Switches and the Fortigate in an Active-Active or an Active-Passive setup but we have run in to issues.
With the Nexus platform of switches, we have two ways to make a connection to devices:
An interface vlan, which creates a distinct vlan on each of the individually managed switches by utilizing Virtual Port Channel technology to give each vlan on each switch its own ip address and a shared HSRP IP address. This works fine, but due to the nature of VPC and the manner in how OSPF uses the actual interface IP address, we have run into a VPC peering issue which does not allow Layer 3 routing information to route correctly over the platform. Because of this we can only set up static routes between the dual redundant Fortigate units and the pair of Cisco Nexus.
We also have the option of running layer 3 ports from each of the Cisco Nexus units individually. This would require each of the switches to have a unique layer 3 address on the port that connects to the Fortigates. In our research, we have only found examples of Fortigates utilizing a shared address.
Is it possible to have a distinct IP address on the internal network ports of the Fortigates when using HA?
Attached is a diagram of what we are attempting to do.
Thanks!
