Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Swapping out HP for Sophos Meraki Switches Patching redundant Ports

Hi, 

We are amidst a network change from HP Curve Switches to Meraki, the network it self is an inherited mess, and am in the process of tracing the cables from our primary and HA Sophos devices, in order to patch into the new Meraki switch.

I would like to know, what the purpose of so many cables from the Primary and HA devices, On the Primary, I have Ports 1-4 filled (with cabling going to the old switch), 5 is empty, Port 6 is the feed from the ISP, Port 7 is the output to my network (this will go into the new switch), Port 8 is going into the HA. I have traced all these cables, and I cant work out that the purpose of Ports 1-4 are, I have the same on the HA. I am trying to limit cables as it is a nightmare. I have been told by the Meraki engineer (who was only here briefly) that there is an LACP channel config on the old switch, and he has configured ports for this on the new switch (one for Primary, one for HA) As I mentioned I have cable soup, and going back to what I was   saying, I cant see a reason to patch Ports 1-4. Please see attached 



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    The main purpose of having hardware setup mirrored is to maintain High Availability(HA) in the event of power, hardware, or software failure. For example, if the primary firewall shuts down for any reason, the current traffic will failover to the secondary firewall. 

    On your firewall, ports 1 to 4 are part of LAG(Link Aggregation Group), and there are VLANs(Sub-interfaces) configured on it. If a primary firewall shuts down or during the firmware updates, to maintain the uninterrupted service, you'd have to have hardware setup mirrored.

    Check out the following KBA for more information: 

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    The main purpose of having hardware setup mirrored is to maintain High Availability(HA) in the event of power, hardware, or software failure. For example, if the primary firewall shuts down for any reason, the current traffic will failover to the secondary firewall. 

    On your firewall, ports 1 to 4 are part of LAG(Link Aggregation Group), and there are VLANs(Sub-interfaces) configured on it. If a primary firewall shuts down or during the firmware updates, to maintain the uninterrupted service, you'd have to have hardware setup mirrored.

    Check out the following KBA for more information: 

    Thanks,

Children