Description

Requirements for connecting two SRX in HA Cluster through Layer 2 Switch

Symptoms

Requirements for implementating SRX HA cluster with Layer 2 witches. One of the nodes is at one site and the other node is at a different site.

Solution

Please refer to the requirements for implementing HA Cluster with Layer 2 Switches in between:

 

++ The Switches must handle a separate Vlan for the Control Port and another Vlan for the Fab Port. These Vlans cannot share transit traffic.

++ Enable Jumbo frames on the Switches. 

++ Disable IGMP Snooping. See document below.

++ The Switch must not perform IP legitimate check

++ Highly recommended using a different switch for the Control Port and another Switch for vlan for Fab Port.

++ Apply the Maximum MTU possible for Fabric link.

++ Latency less than 100ms.

++ At least 1 Gbps link for each port

++ Cluster-ID less than 16. 

 

Modification History

2024-01-02 : Article Created

Related Information

How to configure jumbo frames on the EX/QFX Series Switches

https://supportportal.juniper.net/s/article/How-to-configure-jumbo-frames-on-the-EX-QFX-series-Ethernet-switches

 

disable (IGMP Snooping)

https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/statement/disable-edit-protocols-igmp-snooping-qfx-series.html

 

[SRX/EX] Troubleshooting a SRX chassis cluster that is connected via a layer 2 switch

https://supportportal.juniper.net/s/article/SRX-EX-Troubleshooting-a-SRX-chassis-cluster-that-is-connected-via-a-layer-2-switch

 

Configure Chassis Cluster (High Availability) on the High-End SRX devices: SRX1400, SRX3400, SRX3600, SRX5400, SRX5600, SRX5800

https://supportportal.juniper.net/s/article/Configure-Chassis-Cluster-High-Availability-on-the-High-End-SRX-devices-SRX1400-SRX3400-SRX3600-SRX5400-SRX5600-SRX5800

 

SRX HA Configuration Generator

https://support.juniper.net/support/tools/srxha/