@HarmeshYadav glad to be of help, answers below to your further questions: 1) You are correct, one for primary MX, one for vIP and you do need a third for the second MX. The ISP also needs to use one on the equipment that the line terminates in so effectively the minimum subnet you need is a /29. 2) MX can only be active/active in when deployed purely as a VPN concentrator. Why do you need active/active, with the virtual IP it appears to one firewall to the outside and it always appears as one to the inside. Cheers, Charles
... View more