Setting up the connectivity for chassis cluster on vSRX Virtual Firewall instances is similar to physical SRX Series Firewalls. The vSRX Virtual Firewall VM uses virtual network (or vswitch) for virtual NIC (such as VMXNET3 or virtio).
Chassis cluster requires the following direct connections between the two vSRX Virtual Firewall instances:
* Control link, or virtual network, which acts in active/passive mode for the control plane traffic between the two vSRX Virtual Firewall instances
* Fabric link, or virtual network, which is used for real-time session synchronization between the nodes. In active/active mode, this link is also used for carrying data traffic between the two vSRX Virtual Firewall instances.
Each network adapter defined for a vSRX Virtual Firewall is mapped to a specific interface, depending on whether the vSRX Virtual Firewall instance is a standalone VM or one of a cluster pair for high availability. The interface names and mappings in vSRX Virtual Firewall changes accordingly after it changed from standalone to cluster.
In standalone mode:
* fxp0 is the out-of-band management interface.* ge-0/0/0 is the first traffic (revenue) interface.
In cluster mode:
* fxp0 is the out-of-band management interface.* em0 is the cluster control link for both nodes.* Any of the traffic interfaces can be specified as the fabric links, such as ge-0/0/0 for fab0 on node 0 and ge-7/0/0 for fab1 on node 1.
vSRX Chassis Cluster Interface Mapping as below