Unsolved
14 Posts
0
288
April 16th, 2022 16:00
n3024 Stack as an Intermediate Switch between an internal firewall and a perimeter firewall.
I have an HA Active/Passive Perimeter firewall of PA820 that connects directly with a DMZ ToR 4148-ON switches and a Switch stacked(Dell n3024 Switches with 2x10G stack cable) which goes on to connect with an internal forigate (FG600 series) firewall. So the 3024 is serving as an intermediate or interconnect switch between my perimeter firewall and my internal firewall. So the traffic between the two firewall is switched through this 3024 device with both sides of the connection is done through two port-channel for each firewall(both firewalls in Active/Passive state) and the aggregated group has two LACP members.
I want to upgrade the link speed from the internal firewall to the Switch as well as the Perimeter firewall to this same switch stacks. Unfortunately, the FortiGate has run out of Cu ports and left only with Fiber SFP ports. So If I have to leave this paloalto link as is i.e. only 2x1G Cu UTP to the switch. But the internal firewall has plenty of port space to expand the link aggregation from it to the 3024 switch so I was thinking of upgrading this from 2x1G to 4 or 8x1G. What is bothering me though is what would happen if a high-volume traffic comes out of or into the internal firewall. As this connection is currently a point to point link in a nutshell if the intermediate switch is taken out of the picture. How well will the interconnect/middle switch manage its job as one end has 8G link aggregate and the other end with 2G link aggregate? Would it manage the relay the packets with no drop and without overwhelming itself interms of memory and buffers
Appreciate all your insights!


DELL-Young E
Moderator
•
5.4K Posts
•
37 Points
1
April 17th, 2022 23:00
Hi first of all,
8G to 2G is not recommended first of all because it could trigger performance issues.
I'd say 4G to 2G is ok for this scenario.