Skip to Main Content
IBM Cloud - Structured Ideas


This portal is to open public enhancement requests against IBM Cloud and its products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

IBM Cloud Support Center (https://cloud.ibm.com/unifiedsupport/cases/form) – Use this site for any IBM Cloud defect or support need.

Stack Overflow (https://stackoverflow.com/questions/tagged/ibm-cloud) – Use this site for IBM Cloud technical Q&A using the tag "ibm-cloud".

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Under review
Created by Guest
Created on Sep 19, 2024

NextGen Firewall Multi Node High Availability (MNHA) - Virtual IP

Current setup offered by Juniper vSRX is a chassis-based clustering mechanism (running in classic BareMetal servers) requires a pair of firewalls to be placed in the same transit vlan both physically and logically, connecting the two vSRX firewalls using CTRL and FAB links, placed next to each other.

In the IBM VPC deployment, Juniper vSRX introduces the chassis and user traffic high availability feature called MNHA - Multi Node High Availability which allows the two vSRX which can be installed on bare metal or as a VM in KVM, to reside in separate geographies as well as act as Active/Active instead of Active/Backup as was the case in Chassis Cluster model.

The Juniper vSRX MNHA feature allows four different modes of deployment: Switching, Routing, Hybrid, and Cloud

The current workaround in VPC is to use a VPC Load balancer which not only limits the deployment of vSRX in the same zone but requires a DNS bind when used for end customer deployment.

The most viable option is the "CLOUD" deployment mode allowing vSRX to use a script and intergrate/interact with VPC (management or underlay or other) to confirm when/which vSRX to use for certain traffic flows/data. The VPC can provide a feature such as Virtual IP shared between the two vSRX and update the immediate gateway of the VPC subnet using GARP.

This deployment breaks away from the routine Active/Backup models of firewall deployment by using Active/Active firewalls as well as zone/region redundancy allowing firewalls to exist in other regions. And to top it all, there is almost NO service/traffic impact during failover. The firewall images are available in every region to deploy, without restriction and customized to use as VPC VSI.

Idea priority Urgent
Needed By Month