- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- HPE Aruba Networking & ProVision-based
- >
- MULTICAST MAC-ADDRESS support for firewall cluster
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-17-2013 02:45 AM
06-17-2013 02:45 AM
MULTICAST MAC-ADDRESS support for firewall cluster
hallo
we have to make a firewall cluster in active/active mode ( 2 watchguard firewalls).
Cluster uses MULTICAST MAC- ADDRESS for all interfaces that send network traffic.
We need an hp switch model, possibly layer2 managed, that supports MULTICAST MAC-ADDRESS and does not filter/block theese addresses.
Someone have just done similar configs ?
best regards
Francesco
- Tags:
- firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2014 01:14 PM
01-28-2014 01:14 PM
Re: MULTICAST MAC-ADDRESS support for firewall cluster
Hello,
did you found a solution? I added the multicast mac addresses für external and trusted to our HP A5500 switches (irf-stack) but I get no internet connection
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2014 03:26 AM - edited 01-31-2014 01:09 AM
01-30-2014 03:26 AM - edited 01-31-2014 01:09 AM
Re: MULTICAST MAC-ADDRESS support for firewall cluster
Hi Francesco Soffia_1,
Any layer2 switch should suffice. The Multicast packets are not filtered/dropped. They will be broadcast to all switch ports, so you will just increase you *cast traffic. The best way is to put your firewalls in another VLAN so to limit the casting of the cluster traffic. I am no expert on this topic, so maybe someone else has some input, but I would not see there beign too many issues as long as you have your tagging/routing setup correctly on the firewall cluster ports.
issues may arise if you are trying to connect from outside of the subnet the firewalls are in so you would then need to add static arp entries on routers for the multicast mac address pointing toteh clusters VIP.
HTH
EDIT: not sure if the follwing post will help you at all...
http://h30499.www3.hp.com/t5/ProCurve-ProVision-Based/Static-ARP-entry/td-p/4162889#.Uutn7khFC_4
Don't forget to mark a post resolved if your question was answered.