cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1509
Views
0
Helpful
2
Replies

HSRP between 2 routers with VRRP

ohareka70
Level 3
Level 3

I have 2 routers which sit outside my network that i want to connect directly into the firewall. CPE Router 1 is the active router and CPE Router 2 is the secondary. I have HSRP installed between CPE Router 1 and CPE Router 2. CPE Router 1, CPE Router 2 and the HSRP ip addresses are all on the same subnet. They will both talk to the same servers inside my firewall.

Do i need to have VRRP on the firewall to make this scenario work?  or will i need a switch between the firewall and the 2 x Routers

Q.  Whats the best way to do this?  I have been given some advice that i should disconnect the 2 CPE Routers from the Firewall, and place a Network Switch / VLAN a segment to use for the connection between the Firewall and the 2 CPE devices.

1 Accepted Solution

Accepted Solutions

ravikantt
Level 1
Level 1

HI Kevin,

there should be L2 connectivity between HSRP peers, which is missing over here.

Plus, you can't  make inter-work HSRP on router side & VRRP on firewall side.

option 1: Get direct link betwwen CPE 1 & CPE 2

option 2: Use L2 switch & CPE1 & CPE2 via this

for HSRP, VRRP; you have chosse one of the option & recommeded is option 2 (although it'd involve little more cost)

but will in tshoot, if anything goes wroung.

Cheers

Ashok

View solution in original post

2 Replies 2

ravikantt
Level 1
Level 1

HI Kevin,

there should be L2 connectivity between HSRP peers, which is missing over here.

Plus, you can't  make inter-work HSRP on router side & VRRP on firewall side.

option 1: Get direct link betwwen CPE 1 & CPE 2

option 2: Use L2 switch & CPE1 & CPE2 via this

for HSRP, VRRP; you have chosse one of the option & recommeded is option 2 (although it'd involve little more cost)

but will in tshoot, if anything goes wroung.

Cheers

Ashok

Thanks for your help.  I plugged the two routers into a switch which then plugged into the firewall and HSRP works fine.

Cheers
Kevin

Review Cisco Networking products for a $25 gift card