Hello - Looking for some suggestions here while in the planning stages...
We currently have 1 datacenter, with 2 ISP connections going into a pair of XG550's (an HA Pair). This is working fine today.
We have miles of dark fiber which we light, and plan on standing up a secondary datacenter at another location, with its own ISP connection and firewall. As for the internal networking, the plan is to simply stretch the current datacenter VLAN to the secondary site, and move one of the ISP connections to this site.
Beyond this, I figure some routing changes will be needed internally so that a default route is chosen correctly (either the HA firewall pair at the main site, or the firewall at the secondary site).
I'm having trouble seeing how we can automatically failover to the secondary ISP at the secondary site when basically 2 standalone Sophos XG's are being used. We use EIGRP now on our Cisco cores. Will the firewall's also need to participate in routing somehow, in order to do an ISP failover?
Suggestions appreciated :)
Thanks.
This thread was automatically locked due to age.