Firecluster with Multiwan - Layer 2 switch recommendations

Hello all.

I have a primary and backup ISP, 2x M390s in a Firecluster configuration and want to introduce 2x layer-2 switches ahead of the Firecluster. This will allow me to patch both primary and backup ISP into each M390 (right now both ISPs are patched into the primary M390 directly which doesn't do us much good in the event of a failover).

Question is, has anyone else actually implemented this and do you have any recommendations for a solid but cost effective layer-2 switch? Note that I need 3x SFP+ ports.

Many thanks.

Comments

  • james.carsonjames.carson Moderator, WatchGuard Representative

    In general, for an active/backup cluster, any layer 2 switch will do just fine. Using two separate switches (one for each ISP) is the best way to do this, because trying to do both ISPs on one switch will create a single point of failure.

    I can't recommend any specific brands as an employee, but make sure that whatever device you choose has a management interface, is only accessible via a management port, or is locked down so it can't be accessed internally. Many customers choose dumb L2 switches on their external side for this reason.

    -James Carson
    WatchGuard Customer Support

  • edited September 30

    Thanks James. Appreciate that you can't make recommendations and definitely appreciate the quick response.

    Can't wait to get this set up properly. For the record I'm looking at two of either of these models. We don't want to break the bank but need a solid switch:

    QNAP QSW-M3212R-8S4T-US

    or perhaps:

    MikroTik CRS328-4C-20S-4S+RM

  • Marc C, we currently have 5 ISP feeds (1 is an evaluation) into a M390 cluster and twin switches providing connectivity. My suggestion is to spend adequate money for the task because it will likely return that value many times.

Sign In to comment.