ASA , 3750 Switch stack ,Etherchanel cross-stack and HA

Hi Guys,
I have run into a scenario where there they use a switch stack of four 3750’s and two ASA 5540 in Active-stanby HA Pair.
ASA's are connected with 4 interfaces across stack (1 interface to each switch).
1 Etherchannels (4 ports) is configured between ASA and switch. All vlans are terminated on ASA as a subiterfaces.
somehting like:
Port-channell1
no ip address
Port-channell1.10
vlan 10
ip address 192.168.10.1 255.255.255.0 stanby 192.168.10.2
Port-channell1.20
vlan 10
ip address 192.168.20.1 255.255.255.0 stanby 192.168.20.2
..and so on..
There is about different 60-70 vlans currently terminated on ASA.
We found a problem with failover testing:
When we test the failover and fail manually with “failover active” command,
It looks like only 29 vlans can fail to backup ASA instantly , the rest can take up to 5 min.
Is there a limitation for ASA or 3750 etherchannel  in this scenario why it would not failover instantly for all vlans ?
Thanks
Martin

sory mistake there :
Port-channell1.20
vlan 20
ip address 192.168.20.1 255.255.255.0 stanby 192.168.20.2
Martin

Similar Messages

  • WLC 5508 LAG and CAt 3750 cross stack

    Hello,
    I would like to use the LAG feature on my 5508 WLCs and connect each of them to two different port of a 3750 stack using cross stack. Do you think it will work?
    Cisco suggests not to connect different LAG ports of a WLC to different CAT3750 but it's not clear if it was referred to different standalone 3750s or to a stackwise of 3750s.
    Tnks all
    Johnny

    The HA kicks in when the primary looses gateway, do a small test, keep a continuous ping to WLC  from its gateway as source and break one of the link in the LAG and see if you drop any packet ?

  • 3750 Cross-stack equal cost routes across different switches in the stack

    Hello,
    If I configure a cross stack ethernet channel does it support link aggregation to increase bandwidth or is it just support for link failover?

    Answer is support for link failover.
    The EtherChannel on multiple switches in the Cisco Catalyst 3750 stack is called cross-stack EtherChannel.
    If a link within an EtherChannel fails, traffic previously carried over that failed link changes to the remaining links 
    within the EtherChannel. A trap is sent for a failure, which identifies the switch, the EtherChannel, and the failed link. 
    Inbound broadcast and multicast packets on one link in an EtherChannel are blocked, and cannot return on any other link of the EtherChannel.
    HTH
    Regards
    inayath

  • 3750 switch stacks

    I am new to the networking world and have some questions.
    I have 1 stack of six 3750 switches with a 10.50.3.10 ip address
    On the first stack (.10)I have int 6/0/19 , 20 and 21 assigned.
    I have a second ip scheme with one switch with an ip of 10.50.3.11
    Do I use a smartwise cable to connect the switches even though they have different ip schemes? Or do I use a only a cat 5 to connect the 2 differenet stacks. Also, do I need to configure the 6/0/19, 20 and 21 ports on the second ip scheme. I don't think it is possible now that I am writing this if the smartwise cables are not used. Any help would be appreciated.

    I apologize but I am not following you entirely. If you stack the 3750, you must use the stacking port and use the stackwise cable.
    You said: I have 1 stack of six 3750 switches with a 10.50.3.10 ip address
    >> This would mean you stacked them using the stackwise cable and all these six switches are seen as one single device.
    What do you mean by you have int 6/0/19-21 assigned? Assigned them what?
    You said: I have a second ip scheme with one switch with an ip of 10.50.3.11
    >> Sounds like you have another stack? Because the device will complaint if you address two different interfaces in teh same switch/router to the same subnet (10.50.3.10 and 10.50.3.11), unless these addresses are masked as host but I doubt that.

  • Snmp for 3750 switch stack

    Hi,
    I have two 3750 switch stack together with one ip address mange the stack.
    Can I monitor the memory and cpu for each individual switch? what is the oid then?
    Thanks.
    C.K.

    Hello CK,
    On the Catalyst 3750, the stack master handles the SNMP requests and traps for the whole switch stack.
    The stack master transparently manages any requests or traps that are related to all stack members. When a new stack master is elected, the new master continues to handle SNMP requests and traps as configured on the previous stack master, assuming that IP connectivity to the SNMP management stations is still in place after the new master has taken control.
    So to answer your question, with the OID for CPU and Mempory usage the switch will return only values for the active master. The other stack members are hot standby and do not produce SNMP information for CPU and/or Memory.
    HTH
    --Leon

  • Catalyst 3850 Cross-Stack EtherChannel

    On 3850 configuration guide, I came across PAgP desirable mode is not supported in the switch stack (cross-stack EtherChannel).
    http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/layer2/configuration_guide/b_lay2_3se_3850_cg/b_lay2_3se_3850_cg_chapter_0101.html
    But on Q&A document, it mentioned 3850 supports PAgP.
    Q.    What cross-stack EtherChannel link bundling protocols are supported?
    A.     The Cisco Catalyst 3850 supports Cisco Port Aggregation Protocol (PAgP) and industry-standard IEEE 802.3ad Link Aggregation Control Protocol (LACP). Other 3750 Series Switches support only LACP for cross-stack EtherChannel.
    Seems like both statements are contradicting.
    Can someone shed some light on this?
    Thank you.

    Hi, adimakmur 
    Cisco Catalyst 3850 Cross-Stack EtherChannel can be PAgP+ and can be used for VSS dual active detection.
    In last deployment of 3850 we use Cross-Stack EtherChannel and use it as trusted for VSS dual active detection.
    c6500-V#sh switch virtual dual-active pagp
    PAgP dual-active detection enabled: Yes
    PAgP dual-active version: 1.1
    ----skiped----
    Channel group 106 dual-active detect capability w/nbrs
    Dual-Active trusted group: Yes
              Dual-Active     Partner              Partner   Partner
    Port      Detect Capable  Name                 Port      Version
    Te1/7/7   Yes             c3850-307            Te1/1/3   1.1
    Te2/7/7   Yes             c3850-307            Te2/1/3   1.1
    ---skiped----
    c6500-V#sh etherchannel 106  protocol 
    Protocol:  PAgP
    c3850-307#sh etherchannel port-channel 
                    Channel-group listing: 
    Group: 1 
                    Port-channels in the group: 
    Port-channel: Po1
    Age of the Port-channel   = 235d:20h:50m:10s
    Logical slot/port   = 12/1          Number of ports = 2
    GC                  = 0x00010001      HotStandBy port = null
    Port state          = Port-channel Ag-Inuse 
    Protocol            =   PAgP
    Port security       = Disabled
    Ports in the Port-channel: 
    Index   Load   Port     EC state        No of bits
    ------+------+------+------------------+-----------
      0     00     Te1/1/3  Desirable-Sl       0
      0     00     Te2/1/3  Desirable-Sl       0
    Time since last port bundled:    169d:04h:58m:49s    Te1/1/3
    Time since last port Un-bundled: 169d:05h:00m:47s    Te1/1/3

  • Do I need to create ip address to another switch when i use stack?

    Good Day!
    Please help me to answer this question in my title. I have 2 switches my old switch has configure ip address and i will use stack to my another switch the old one will be the primary and new switch is the secondary do i need to configure the ip address of the new 1 or  no need? i'm totally confuse on it. I hope you can help me regarding on this matter.Thank you.

    no Need.
    Here is the procedure:
    Tips to Add a Switch as a Slave to the Stack
    To add a switch, as a slave, to a stack, complete these steps:
    Note: Make sure the switch that you add into the stack has the same IOS version as the switches in the stack. Refer to Catalyst 3750 Software Upgrade in a Stack Configuration with Use of the Command-Line Interface to upgrade the IOS in a catalyst 3750 switch.
    Change the switch priority of the switch to be added to "1".switch stack-member-number priority new-priority-valueNote: This step is optional, but it will make sure that the switch has fewer chances to become a stackmaster in the future.
    Power off the switch that is to be added.
    Make sure that the stack is fully connected so that, when you connect the new switch, the stack will be at least in half connectivity and does not partition.
    Connect the new switch to the stack with the StackWise ports.
    Power on the newly added switch.
    After the new switch comes up, issue the command show switch to verify stack membership.
    HTH
    Regards
    Inayath
    ***********Plz dont forget to rate all usefull posts*********

  • Adding switch into an existing stack

                       Hi all,
        I have an existing stack which comprises of 6 switches, please help with the following questions :
    1/ adding another switch into this stack will cause all switches in stack to reboot ? anything that I should be aware of such as different versions ?
    2/ maximum switches in one stack should be ?
      Thanks for all help.

    Hi Duc,
    If you are stacking 3750 switches you can have a max of 9 switches in one stack. The only thing you have to make sure before adding the new switch is that its IOS version should be exactly same as the IOS version of rest of the stack.
    You dont have to worry about any reload of existing stack. Connect the stack cables to the new switch, power it up and it will be added to the existing stack.
    http://www.cisco.com/en/US/products/hw/switches/ps5023/products_configuration_example09186a00807811ad.shtml
    Thanks
    Ankur
    "Please rate the post if found useful"

  • SG500 cross stack etherchannel

    Is it possible to configure a cross stack etherchannel between 2 SG500 (in stack) and 1 SG200/SG300?

    Hi all, I was wondering the exact same thing, I'm considering a similar design but doing an etherchannel between two cross-stacked SG500X and 3 UCS servers (C240 M3). Something like this:
    |              |                                  |                 |
    | UCS      |----------------------------------| SG500X    |
    |  C240     |                                 |__________|
    |  M3        |                                   __________
    |              |                                  |                 |
    |              |----------------------------------| SG500X    |
    |________|                                  |__________|
    I don't know if these switches could support this kine of cross stacked etherchannels, if it does then I'm guessing it's the same whether it's a server o a switch connected to it. Thanks in advance
    Edit: Sorry for the ugly ascii drawing I just did on a whim...    
    El mensaje fue editado por: Eric A. Hernandez Gonzalez

  • Best way to migrate cross stack etherchannel mode "on" to "active"

    Hey guys,
    I've a cross stack etherchannel with mode on between two datacenters and now want to switch to LACP.
    Can I just go into the physical interfaces and do a "no channel-group X mode on" -> "channel-group X mode active" or will I have to shut the ports down or completely remove the Port-Channel interface? Can't find any migration document around and don't have test equipment here. :(
    Any ideas?
    Thanks! :)

    Sure, Switch-A:
    Switch Ports Model              SW Version            SW Image
    *    1 30    WS-C3750X-24       12.2(55)SE1           C3750E-UNIVERSALK9-M
         2 30    WS-C3750X-24       12.2(55)SE1           C3750E-UNIVERSALK9-M
    interface GigabitEthernet1/0/1
     description X
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 18,60,64-66,68,100-102,104,105,200,251,900,902
     switchport trunk allowed vlan add 903,906,911,934,937,939
     switchport mode trunk
     channel-group 2 mode active
    end
    interface GigabitEthernet2/0/3
     description X
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 18,60,64-66,68,100-102,104,105,200,251,900,902
     switchport trunk allowed vlan add 903,906,911,934,937,939
     switchport mode trunk
     channel-group 2 mode active
    end
    interface Port-channel2
     description X
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 18,60,64-66,68,100-102,104,105,200,251,900,902
     switchport trunk allowed vlan add 903,906,911,934,937,939
     switchport mode trunk
    end
    Switch-B:
    *    1 30    WS-C3750X-24       15.0(1)SE2            C3750E-UNIVERSALK9-M
         2 30    WS-C3750X-24       15.0(1)SE2            C3750E-UNIVERSALK9-M
    interface GigabitEthernet1/0/1
     description Y
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 18,60,64-66,68,100-102,104,105,200,251,900,902
     switchport trunk allowed vlan add 903,906,911,934,937,939
     switchport mode trunk
     channel-group 1 mode active
    end
    interface GigabitEthernet2/0/1
     description Y
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 18,60,64-66,68,100-102,104,105,200,251,900,902
     switchport trunk allowed vlan add 903,906,911,934,937,939
     switchport mode trunk
     channel-group 1 mode active
    end
    interface Port-channel1
     description Y
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 18,60,64-66,68,100-102,104,105,200,251,900,902
     switchport trunk allowed vlan add 903,906,911,934,937,939
     switchport mode trunk
    end

  • Add 3850 Switch to existing Core Stack

    Hello,
    I need to add a 3850 to our collapsed core Current setup - 5-3850 stack switches with vlans and routing enabled.
    We are in need of more ports and I purchased a 3850.
    I will add the switch to the core via a trunk port
    I will make vtp transparent
    I will configure the magt vlan 10 with an IP addess.
    QUESTION.
    After this is done, do I make the switch VTP client?
    Also, do I turn on IP routing? Or, with the trunk send all packets destined for other vlans over the trunk to the core, and the core will hanle routing?
    I am talking about routing between vlans, so user vlan 64 can talk to vlan 64.
    I have been doing routing on WAN so long I have forgotten best practices on the LAN and L3 Switching.
    OR.....
    Do I simply add this to the switch stack?
    Thank you for any help!
    -T
    Any help is appreciated.

    When you add a switch to an existing stack it gets all of its configuration from the stack master.
    Just verify it has the same IOS version installed (and doesn't have switch priority set such that it takes over as master) and plug it in via the stacking cables.
    If you're adding it as a new access switch then yes just trunk all the VLANs across the uplink to the core. If you have a VTP server setup then set your VTP domain and come up in client mode. If the routing is active on the core and your VLAN SVIs are all there, there's no need for routing on the access layer and the only SVI you need is for management (or use the dedicated management interface for out of band management in its own VRF).

  • 2960S Cross Stack Etherchannel Issues

                       We have a stack of 3 2960S's switches connected to a Cisco 3750X via a 4 port copper Etherchannel, intermittently the users are losing connection to the internet and with a host connected to the Master switch running a continuos ping to the 3750X pings are lost, we have replaced the Master switch and both GLC-T's. We also split the stack and had a single 1Gb connection to each switch from the core, we ran continuos pings from hosts on each switch and the only one to drop pings was the one on the Master switch. Versions and configs below, any thoughts ?
    Version 3750X - 15.0(2) SE4
    Version 2960S - 15.0(2) SE5
    Port-Channel Config 3750X in attached file called 3750x
    Port-Channel Config 2960S in attached file called 2960s
    Also auto QoS has been enabled on both 3750X and 2960S.
    Nothing appears in the logs on both switches.

    Leo/Umesh,
                          Again thanks for the replies, I did a continous ping from a PC connected to the switch stack to an address on the Internet, I also had a continous ping going from another client on a different switch stack to the same internet address. The PC connected to the suspect switch stack dropped about 15 pings but the other PC was fine. I've now set up two syslog servers with the stack logging to one and the core to the other, also I've changed the stack master to be the middle switch which has no up links connected to it. Customer will start monitoring on Monday.

  • Whats the difference between ABAP stack, ABAP+Java stack and Java stack

    Hello,
    I have a nagging doubt about the difference between the ABAP stack, ABAP+Java stack & the Java only stack. I believe that the method of applying the kernel for all the 3 types is different.
    Also can we apply the ABAP support packs through JSPM.
    Please put some light on this.
    Thank you

    Hi Zaheer
    ABAP Stack
    AS ABAP is used to provide the ABAP foundation of SAP NetWeaver.
    Part of AS ABAP is the Search Engine Service (SES), which enables users to search for
    business objects using Search and Classification (TREX). SES accesses Search and
    Classification (TREX) functions through the Search and Classification (TREX) ABAP
    client. SES replicates the business objects from the ABAP application to Search and
    Classification (TREX), so that it can apply Search and Classification (TREX) search
    functions to them. When a user enters a search query, the Search and Classification
    (TREX) system responds to it, not the database for the ABAP application. For more
    information, see the document Installation Guide – SAP NetWeaver TREX Single Hosts /
    Multiple Host.
    Java stack
    AS Java is used to provide the Java foundation of SAP NetWeaver. Among the key
    capabilities of AS Java are:
    • J2EE Engine – a J2EE 1.3-compliant application server for running enterprise
    applications. In addition to the pure J2EE standard technologies, the J2EE
    Engine implements complementary technologies, such as Web Dynpro or Web
    Services, that are targeted at supporting large-scale, real-business application
    development projects.
    • SAP Composite Application Framework Core (CAF Core) is a service-oriented
    architecture for building and deploying composite applications. It enables
    modeling of different service types – entity services that represent a domain
    model, application services that implement business logic, and external
    services that offer connectivity to back-end services by means of remote
    function calls (RFCs) or Web services. Usage type AS Java comprises the CAF
    Core runtime environment, while design time tools are part of the SAP
    NetWeaver Developer Studio.
    • Web Dynpro is the user interface technology for developing professional
    business applications for mobile as well as for desktop clients. Web Dynpro
    applications can easily be integrated into SAP NetWeaver Enterprise Portal,
    providing a unified layout for the end user as well as enhanced navigation
    support. Web Dynpro also allows, for example, the development of interactive
    forms using the Adobe document services.
    • Adobe document services is a set of runtime services that provide a range of
    form and document creation and manipulation functions such as:
    • Converting XML form templates (created using Adobe LiveCycle Designer)
    to PDF and various print formats
    • Setting Adobe Reader rights to enable users to fill in and annotate forms,
    save and print them locally, and include digital signatures for authentication
    using the free Adobe Reader software
    Extracting data from SAP applications into Interactive Forms and transferring form data
    back into SAP applications using XML
    ABAP + Java Stack
    Contains both functionalities.
    I hope this helps
    Regards
    Chen

  • PI 7.31 Dual Stack Using BPM/BRM and ccBPM

    Hello,
    My client has decided to use SAP PI 7.31, because we have many ccBPM solutions, being used a long time, the idea is install the Dual Stack solution and keep using the ccBPM, at least for while.
    But for the new integration solutions, we would like to use the AEX(Local AEX-Based) and connect to BPM and BRM, and maybe migrate the old solutions when possible.
    Is it possible, use the both solutions( AEX/BPM/BRM and ccBPM) ? In this case, we will have all the benefits and great perfomance
    when using the AEX/BPM/BRM(Local AEX-Based) solution, that we have in the single stack ?
    Best regards,
    Dylon.

    Hi, vishal jain.
    Thank you! Checking your link, we will probably choose the third case:
    If PI is installed as dual-stack, then PO, PI and BPM/BRM, will have to be installed with different SIDs.  PI on one SID and BPM/BRM on a different SID.
    But the question remains... in this case is possible to use ccBPM and BPM/BRM, ok ?
    And when using the BPM/BRPM, how is the performance and benefits ?
    Are the same when using single stack solution ?
    Best regards!

  • When I enter time machine (on Time Capsule) i see the stack of screen shots and the time line. However, when I roll over the mouse pointer, the time line does not activate. The cancel button does not get me out of the app: have to alt cmd esc. Ideas?

    When I enter time machine (on Time Capsule) i see the stack of screen shots and the time line. However, when I roll over the mouse pointer, the time line does not activate. The cancel button does not get me out of the app: have to alt+cmd+esc. Ideas?

    I have never seen it but then I run SL which is much more reliable than Lion..
    See
    http://pondini.org/TM/E4.html
    Check the master guru of all TM problems.

Maybe you are looking for

  • Default PR document type to PO

    Hi I have a requirement, Like this doc. type for PR and P.O is ZABC, while doing P.O I want ZABC should default. Any clue. Thanks & Regards Sudhansu

  • Pal or NTSC in HD

    There is a difference between pal and ntsc in the PMW-Ex1 camera? If I shot 1080p30 (only in ntsc setup) and then render the footage to prores, there is a difference to downscale to a sd pal or ntsc? Message was edited by: FranTex

  • Return of consignment using inter-company vendor

    Hi All, I need some help regarding consignment return in retail using inter-company vendor. I'm using item category NKN for fill-up and NKR for pick-up with movement type 635 & 636. The fill up process goes well, we can create the DO fill up using in

  • Before I use Time Machine

    I have a quick question that maybe one of you could answer. I have an external HD, and before I did a clean install, I backed everything up but dragging and dropping my files in my HD to my external HD. Now, after doing a clean install with Leopard,

  • Am I missing out on higher potential speeds?

    I'm an existing Infinity customer on Option 2 - very close to the cabinet and have had an excellent ~38Mbps DL connection since I joined.  Having seen they are rolling out "Infinity 2" I wondered if I would be automatically upgraded to the faster ser