Netgate Firewall And Huawei Switch Fusion Technology

Netgate Dual-Machine CARP Firewall Huawei S5735-S48P4XE-V2 CSS Stacked Dual-Core High Availability Solution

The whole setup implements an external network border firewall, core internal network switching, and full three-layer link redundancy to eliminate single points of failure. It's suitable for mixed scenarios like office work, POE wireless APs, surveillance, and business servers.

1Hardware-level redundancy to eliminate single points of failure in the whole system

Firewall-level dual-machine redundancy

Two Netgate pfSense devices form a CARP active-passive cluster. If either Netgate goes completely offline due to power loss, hardware failure, or system crash, the other device automatically takes over, so a single firewall failure won't cut off internet access for the whole network.
Compared to a single firewall setup: if a single firewall fails, the entire internal network loses connection; this solution avoids that risk.

Core switch full-machine redundancy (CSS cluster)

Two S5735‑S48P4XE‑V2 switches are stacked in CSS mode, with one as the primary and one as the backup. If the primary switch has a hardware failure or power outage, the backup switch automatically takes over all forwarding tasks, and the internal network VLANs, gateways, and Layer 3 forwarding remain uninterrupted. This setup no longer depends on a single core switch, eliminating the risk of the entire internal network going down if one core switch fails. The devices are interconnected with multiple paths, avoiding a single-link bottleneck, and each Netgate firewall connects to both core switches at the same time. Even if one core switch fails, firewall traffic can still be forwarded through the other switch, preventing the single point of failure where "the firewall is only connected to one switch, and if that switch goes down, the whole network goes down.

2. Automatic failure switching, no manual intervention needed, minimal impact on operations

Firewall CARP Switch
Through CARP virtual IP, the pfsync session table is synchronized. If the main firewall fails, the backup takes over the virtual IP within seconds; TCP session tables are synced, keeping most ongoing connections intact so users hardly notice. No need for admins to manually change settings or plug/unplug cables—the switch happens automatically when a failure occurs.

Huawei CSS stack converges in milliseconds

The CSS cluster's internal protocol handles failure convergence, so if the primary box goes down, the backup box takes over the forwarding plane immediately, converging much faster than traditional VRRP. On the downstream side, the LACP aggregated links automatically remove faulty member links, allowing the service to quickly recover.

Supports multiple WAN external network redundancy

With dual ISP connections, if one ISP's external network goes down, pfSense automatically switches to the other ISP, so internal network access to the internet isn't affected by ISP outages. Value: If hardware fails at night or on holidays, no staff need to be on-site to handle it, and services keep running on their own, reducing downtime.

3. Unified Configuration Management to Reduce Human Operation and Maintenance Errors

Netgate Configuration Auto-Sync

Using XMLRPC, the main firewall’s configuration is automatically synced to the backup device. All policies, NAT, VPN, and port forwarding only need to be set up on the main device;

the backup device is not allowed to modify configurations manually, preventing any inconsistencies between the two firewalls that could cause business disruptions.

Huawei CSS Stacking Unified Configuration

Two physical switches are virtualized into a single logical device, so only one set of configurations is needed. VLAN, DHCP, ACL, and QoS only need to be configured once, and they are automatically synced to both pieces of hardware. Compared to the VRRP dual-device setup: VRRP requires each switch to have a full set of configurations, which can easily lead to hidden issues due to VLAN or ACL mismatches; CSS reduces configuration errors right from the start.

4. Support Business Non-Stop Maintenance and Upgrades (Online Operations)

Firewall Rolling Upgrade

The whole setup is in an active-standby mode: first, upgrade the standby Netgate, then manually switch the business to the standby device; after that, upgrade the original primary firewall. The entire process keeps the business running, achieving zero downtime for firmware upgrades.

CSS Switch Rolling Maintenance

CSS stacks support offline maintenance for a single unit. You can migrate traffic to the backup unit, power off one S5735 switch, replace its optical module, upgrade the firmware, while the other switch handles all the traffic, keeping the business network uninterrupted. This is suitable for scenarios where business operations cannot be interrupted, so there is no need to wait for late-night maintenance windows to service equipment.

5. Flexible business access and tiered high availability for different services

Servers: Cross-device LACP aggregation
Business servers have dual network cables connected to two S5735 switches, configured with cross-device LACP link aggregation. If any cable or switch fails, the server network stays online, which is ideal for critical services like ERP or file servers.
Wireless APs and key terminals: Dual power and dual access
Important APs connect to the PoE ports of two switches. If one switch loses power, the other continues to supply power and forward traffic, keeping the wireless network available.
Regular office terminals
Ordinary PCs and standard monitoring devices connect via single PoE, sufficient for daily use. Any failures only affect devices directly connected to the failed switch, preventing a full network outage.

6. Balancing Security Protection and High Availability

Netgate pfSense acts as the boundary, providing unified firewall policies, NAT, intrusion prevention, WireGuard/IPsec VPN, and traffic management; security policies are synchronized with the CARP cluster, so they remain fully effective even after a failover.
Huawei switches on the internal network handle Layer 2 and Layer 3 security: port isolation, ACLs, DHCP-Snooping, and internal network security capabilities follow CSS cluster redundancy.
Many high-availability solutions focus only on keeping the network up, ignoring security; this solution ensures both boundary security and internal switch redundancy, so security policies don’t break after a switch.

7. Hardware Capability Matching Business Scenarios

7.1  Huawei S5735-S48P4XE-V2 comes with 48 Gigabit PoE ports and 4 10G SFP ports:
    With CSS stacking, the overall forwarding capacity is improved, meeting the power and forwarding needs of lots of PoE APs and surveillance cameras.
    10G stacking links ensure internal cluster forwarding bandwidth, so it won't be a performance bottleneck.

  • 48 PoE ports (30W) can power APs, surveillance cameras, and IP phones. Total PoE power can be 600W or 1000W, perfect for lots of connected devices.

  • 4 10G SFP uplink ports don't take up regular ports, can directly connect to aggregation/firewall, supporting high-bandwidth uplink, 10G fiber, and 10G DAC copper cables.

  • Independent hardware stacking ports (2×12GE).

  • Three power slots support N+1 redundancy. Dual power supplies work together, if one fails, the device keeps running. Essential for enterprise high availability.

  • 1U rack-mountable, mature cooling channels, standard server room rack deployment.

7.2 Netgate Active-Passive Setup, performance limit determined by a single device, meets the border gateway needs of small and medium-sized enterprises.
      Netgate pfSense Plus Software Advantages (Netgate Exclusive Commercial Edition)

a. No Function Licensing Restrictions
    No charges based on user numbers, tunnels, or firewall rules; IPSec tunnels, multi-WAN, HA high availability, load balancing are all built-in, no extra licenses needed, saving a lot compared to Huawei, H3C, Fortinet.
b. Mature High Availability HA (CARP)
    Supports dual-device hot standby with CARP, automatic configuration sync, perfectly compatible with two Huawei S5735 Layer 3 switches in a network setup; automatic failover, ideal for core border production environments.
Note: This is state-synced high availability, sessions can migrate, with minimal business interruption.
c. Complete Security Capabilities
    Stateful firewall, IDS/IPS (Suricata), threat filtering Threatgate (new version replacing pfBlockerNG), IP geo-blocking, domain threat filtering.
VPN supports all protocols: WireGuard, IPsec, OpenVPN, capable of site-to-site and remote employee access.
Rich plugin ecosystem: traffic monitoring, bandwidth control, DNS filtering, proxy, etc.
d. Modern Web UI and CLI
    The new Web interface is rewritten in Go, smooth even with tens of thousands of rules; also supports CLI, REST API, can automate batch operations with Ansible.
e. Official Firmware Optimized for Hardware
    Netgate hardware is deeply optimized for pfSense Plus, with official continuous security patch updates, and comes with TAC Lite technical support.

8. Fault Isolation, Controllable Fault Impact

When a fault occurs, it is confined to a single piece of hardware:
If one firewall fails: switch to the other one, and the entire network service is preserved;
If one core switch fails: the other switch in the cluster takes over. Only devices connected to the failed switch's PoE ports are interrupted, while the rest of the internal network, servers, and wireless network continue running. There won’t be a catastrophic situation where a single point of failure brings down the entire network.