Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LAG - Move from 1GB to SFP Ports

Hello

I have a pair of XG330's in HA mode (Active/Passive). I'm running V18.0.4 MR-4

Currently these are connected to my Core switch in a LAG LACP 802.3ad (Ports 4+8) and we have 11 VLAN's configured on this LAG interface.

We have just purchased new Core switches and now have 10GB ports. I want to move the current LAG from the 2 x 1GB Ethernet to the 2 x SFP ports and I'm wondering what is the best way to accomplish this?

My migration process would be:

  1. Add the new SFP ports to the XG's and make sure the interfaces come up.
  2. Configure the Core switch ports for the required VLANS.
  3. Add the new SFP ports to the current LAG Member Interface.
  4. Remove the old 1GB (Ports 4+8) Ethernet from the LAG to leave only the SFP's behind.

Will this work with the new enhancements to the LAG set-up without causing disruption? 

My understanding with V18 is that we can now add Member Ports to a LAG without breaking the HA.

https://docs.sophos.com/nsg/sophos-firewall/18.0/releasenotes/en-us/nsg/sfos/releaseNotes/rn_EnhancedHA.html

Regards

Drobo



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Adding a new interface in LAG flaps all the member interfaces.

    Enhanced HA allows you to add/remove monitored interface(System services > High availability > Select ports to be monitored).

    I'd suggest following below migration process.

    1. Remove LAG interface from HA monitoring list.
    2. Add the new SFP ports to the XG's and make sure the interfaces come up.
    3. Configure the Core switch ports for the required VLANS.
    4. Add the new SFP ports to the current LAG Member Interface.
    5. Remove the old 1GB (Ports 4+8) Ethernet from the LAG to leave only the SFP's behind.
    6. Add LAG interface back to HA monitoring list.

    Hope this helps!!

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Adding a new interface in LAG flaps all the member interfaces.

    Enhanced HA allows you to add/remove monitored interface(System services > High availability > Select ports to be monitored).

    I'd suggest following below migration process.

    1. Remove LAG interface from HA monitoring list.
    2. Add the new SFP ports to the XG's and make sure the interfaces come up.
    3. Configure the Core switch ports for the required VLANS.
    4. Add the new SFP ports to the current LAG Member Interface.
    5. Remove the old 1GB (Ports 4+8) Ethernet from the LAG to leave only the SFP's behind.
    6. Add LAG interface back to HA monitoring list.

    Hope this helps!!

Children