u/SuddenVegetable8801

Passive HA Pair - managing the passive member without an extra switch

Hey all,

Looked back a little bit in the forum and there's a couple of mentions of this scenario here and there, but just wanted to float the situation and possible solutions.

We've got an Passive HA pair of firewalls deployed at a manufacturing partner, and we establish management connectivity over an IPSec tunnel. ***EDIT: No panorama or SCM here, this is locally managed

Due to rackspace constraints, we could not spec a switch to facilitate access to the management ports (1u of space, we're using two small 500 series units). And we are currently not being allowed to patch the management interfaces for our firewalls out to the factory floor.

Am I missing something by thinking I can set up an L3 interface on my firewalls on an unused port (port 6 for example) and cross connect the firewalls (FW1 MGMT to FW2 port 6 + FW2 MGMT to FW1 port 6)? Then I can just set a static IP on each management interface and ensure that the routing and rules are enabled to facilitate connectivity over the tunnel?

It's not ideal, but am I missing anything major about this? I know that I won't be able to access both firewalls at the same time this way, as the data plane interfaces will be down on the passive member, but I already have connectivity to manage the primary firewall via the tunnel.

Anyone else overcome this solution (besides just getting a switch, or having them patch the mgmt interfaces out into their network)?

reddit.com
u/SuddenVegetable8801 — 9 days ago