Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connection of two FW in a HA Cluster

Hello Community,

it's quite easy to connect two Firewalls to have a HA Cluster.

But the next step is to connect every port of both Firewalls to the corresponding network.
It's still quite easy to connect e.g. both LAN and DMZ ports to the LAN and DMZ switches.
The switches have enough ports and at one time only one Firewall port is active.

But I wonder how to connect both Firewalls to WAN, when having only one cable/port.
Some admins put a 5 port mini switch between WAN port and both Firewalls.
But this "feels" a little bit "crazy" to me...
Two "big, powerfull HA configured Firewalls" and they depends on a 10 EUR mini switch...

Now I found a "crazy" RJ45-Y-Cable, which could be a solid mechanical solution.
This is NOT a 8 to 2x 4 splitter (e.g. to connect two ISDN Phones with one LAN port)!
This is a real 8 to 2x 8 "duplicator".
I don't know, how this can be useful in "real LAN life", but it could be THE solution for connecting two active-passive Firewalls with one WAN port!

But I'm not sure, if the passive Firewall/port is realy passive/deactivated (LAN/logical & electrical).
Of course, I don't want to short-circuit both Firewall ports...!

Do have anybody experience with such a RJ45-Y-Cable/"duplicator"?
Or do have anybody another idea?

Thanks!
Eric Hencker



This thread was automatically locked due to age.
Parents Reply Children
  • Good Morning,

    both Firewalls and the WAN gateway are together in one rack and so I was looking for a solution in this "near field".

    Using 3 ports with VLAN tagged in of the existing "big" switches in the neighbor rack is so easy!

    There is a german proverb:
    You can't see the forest for the trees.

    Thanks for expanding my view!
    :-)

    Eric