I am trying to configure a pair of SSG350 firewalls to provide redundancy. I have attached two diagrams for reference. One diagram shows a single connection to each service provider and the other shows each firewall dual connected.
I have successfully configured the firewalls in active/passive mode, with a single service provider (SP) connection on each. I can use IP monitoring to force a device failover if my primary SP becomes unavailable. That all works well.
What i want to try to accomplish now is to have each firewall connected to both SPs with interface failover for a circuit failure and device failover for device failure.
With a single firewall and two SPs, I can use the interface monitor featrure on the primary circuit and set two default routes with different preferences - a higher preference for the primary circuit. If the primary circuit fails (IP monitor fails), the secondary route becomes active. I have also successfully configured this.
In an HA configuration, however, the interface IP monitor function doesn't appear to be configurable - only the NSRP IP monitor funtion is available. So, in an HA configuration I'm not sure how to connect both SPs to each firewall and have the circuit fail (not the device) without the use of a dynamic routing protocol. I think that device failover is functionally equivalent, but would like another perspective. Any ideas would be greatly appreciated.
Regards,