Requirements for Vegas

Configuration Requirements for New PAs

Initial Status

  • Two firewalls are licensed and upgraded to the correct OS.

  • Configuration will mimic the Texas location, which will eventually shut down once Vegas is fully operational.

  • Internal networks will remain the same.

  • Configuration changes will primarily be for public-facing elements.

Public IPs and Domain

  • New public IPs are needed for the interface and GlobalProtect.

  • The same domain or FQDN will be used; DNS changes will point to the new public IP address.

Management Network

  • Confirmation is needed from NexusTech regarding the management network.

  • The same address spaces internally will be maintained, as controlled by NexusTech.

  • An additional internal address is required for the LAN interface of the second firewall in the pair.

ISP Connection

  • A single ISP connection will be used (100 meg connection feeding into this).

Configuration Steps

  • Verification is needed for the management network IPs (primary and secondary) and public IPs.

  • Interfaces will be configured with Ethernet one on the inside and Ethernet two on the outside for the public side.

  • Once configured, the firewalls can be shipped.

Verification and Testing

  • After racking and mounting, on-site personnel will verify access to the management network.

  • Testing will then commence.

Diagram and IP Information

  • A diagram is needed to show NexusTech which interface should be connected to which switch.

  • The diagram will include the new IP information for future reference.

Internal Network Confirmation

  • NexusTech indicated the internal side would remain the same, but confirmation is still needed.

  • The public address changes will be implemented.

Discovery Call

  • A discovery call with Castle and Igor is needed after gathering answers from NexusTech.

  • Leverage Justin, a remote hands resource in Vegas, for AT&T MeetMe room coordination; Joseph Castle can be a backup resource.

IPSec Tunnel and Access

  • Internal management is accessed via an IPSec tunnel over the public connection.

  • Correct public information is crucial for establishing the tunnel.

Firewall Configuration Loading

  • The base configuration (excluding public information) will be loaded into the firewalls.

Rack System and Pairing

  • Racks for the firewalls (1U setup) have been ordered to house the power supplies and two PAs.

  • The rack system's fit will be tested.

  • The pairing will be configured in the lab; configurations will be copied to the secondary firewall.

  • The diagram will detail interface connections for pairing.

HA Pair Connectivity

  • Unlike the 820s, these models do not have a dedicated interface for an HA connection. Instead, the HA connection will utilize the existing interfaces, which necessitates careful planning to ensure bandwidth requirements are met. .

  • The management connection can be used for HA1, with a backup pathway created via the same network.

  • A straight cable from Ethernet 1/9 on both firewalls can create a second physical backbone for backup and syncing.

U Cost Savings

  • The 1U rack setup saves on monthly U charges (approximately 3,0003,000 per year).

HA Pair Connectivity Considerations

  • For HA pair connectivity, the existing connectivity for the management interfaces should be used.

  • An alternative involves a direct cable connection between the two firewalls for redundancy.

  • Typically, firewalls would be connected to different switches for redundancy, but a direct cable provides a backup.

Next Steps

  • Gather public information to finalize configurations.

  • Test and preset to verify readiness.

  • Leroy to follow up with Igor or open a ticket to confirm the second IP.

  • Schedule a discovery call with NexusTech.

Circuit Delivery

  • The circuit is expected to be delivered mid-July.

Action Items

  • Kevin: Load the base configs on the firewalls.

  • Jeff and Leroy: Requested a diagram on what interfaces connects to what for the NexusTech when they receive the hardware and they need to do the physical connections.

  • Leroy: Gain confirmation from Nexus on the second IP.

  • Schedule a discovery call with Nexus Tech.