Requirements for Vegas
Configuration Requirements for New PAs
Initial Status
Two firewalls are licensed and upgraded to the correct OS.
Configuration will mimic the Texas location, which will eventually shut down once Vegas is fully operational.
Internal networks will remain the same.
Configuration changes will primarily be for public-facing elements.
Public IPs and Domain
New public IPs are needed for the interface and GlobalProtect.
The same domain or FQDN will be used; DNS changes will point to the new public IP address.
Management Network
Confirmation is needed from NexusTech regarding the management network.
The same address spaces internally will be maintained, as controlled by NexusTech.
An additional internal address is required for the LAN interface of the second firewall in the pair.
ISP Connection
A single ISP connection will be used (100 meg connection feeding into this).
Configuration Steps
Verification is needed for the management network IPs (primary and secondary) and public IPs.
Interfaces will be configured with Ethernet one on the inside and Ethernet two on the outside for the public side.
Once configured, the firewalls can be shipped.
Verification and Testing
After racking and mounting, on-site personnel will verify access to the management network.
Testing will then commence.
Diagram and IP Information
A diagram is needed to show NexusTech which interface should be connected to which switch.
The diagram will include the new IP information for future reference.
Internal Network Confirmation
NexusTech indicated the internal side would remain the same, but confirmation is still needed.
The public address changes will be implemented.
Discovery Call
A discovery call with Castle and Igor is needed after gathering answers from NexusTech.
Leverage Justin, a remote hands resource in Vegas, for AT&T MeetMe room coordination; Joseph Castle can be a backup resource.
IPSec Tunnel and Access
Internal management is accessed via an IPSec tunnel over the public connection.
Correct public information is crucial for establishing the tunnel.
Firewall Configuration Loading
The base configuration (excluding public information) will be loaded into the firewalls.
Rack System and Pairing
Racks for the firewalls (1U setup) have been ordered to house the power supplies and two PAs.
The rack system's fit will be tested.
The pairing will be configured in the lab; configurations will be copied to the secondary firewall.
The diagram will detail interface connections for pairing.
HA Pair Connectivity
Unlike the 820s, these models do not have a dedicated interface for an HA connection. Instead, the HA connection will utilize the existing interfaces, which necessitates careful planning to ensure bandwidth requirements are met. .
The management connection can be used for HA1, with a backup pathway created via the same network.
A straight cable from Ethernet 1/9 on both firewalls can create a second physical backbone for backup and syncing.
U Cost Savings
The 1U rack setup saves on monthly U charges (approximately per year).
HA Pair Connectivity Considerations
For HA pair connectivity, the existing connectivity for the management interfaces should be used.
An alternative involves a direct cable connection between the two firewalls for redundancy.
Typically, firewalls would be connected to different switches for redundancy, but a direct cable provides a backup.
Next Steps
Gather public information to finalize configurations.
Test and preset to verify readiness.
Leroy to follow up with Igor or open a ticket to confirm the second IP.
Schedule a discovery call with NexusTech.
Circuit Delivery
The circuit is expected to be delivered mid-July.
Action Items
Kevin: Load the base configs on the firewalls.
Jeff and Leroy: Requested a diagram on what interfaces connects to what for the NexusTech when they receive the hardware and they need to do the physical connections.
Leroy: Gain confirmation from Nexus on the second IP.
Schedule a discovery call with Nexus Tech.