<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 4500X VSS in Switching</title>
    <link>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088332#M387286</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A typical Data Center ASA cluster with vPC and VSS(file attached)&lt;/P&gt;
&lt;P&gt;All interfaces and port-channels are up, vPC, VSS, Cluster all OK.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. From Core-S1 Vlan 200 I can reach Vlan 200 on Servers LAN&lt;BR /&gt;2. From Core-S1 Vlan 200 I can reach ip 10.44.124.1 (Vlan124 on Core-S4)&lt;BR /&gt;3. From Core-S1 some traffic to Vlan 124 are ok and some not&lt;BR /&gt;4. From Core-S4 Vlan 124 some traffic to Vlan 124 are ok and some not&lt;BR /&gt;5. If I disable Te1/1/10 and Te1/2/7, vlan 124 is reachable from Core-S1&lt;BR /&gt;6. If I enable Te1/1/10 and Te1/2/7 and disable Te2/1/10 and Te2/2/7, some &lt;BR /&gt;traffic to vlan 124 are ok and some not.&lt;BR /&gt;7. If I move trunk from Core-S1 to Core-S4 with interfaces Te2/1/10 and Te2/2/7 disabled, vlan 124 is reachable.&lt;BR /&gt;&lt;BR /&gt;Do I need special configuration for L3 routing on VSS?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 20:13:13 GMT</pubDate>
    <dc:creator>Eugen Bitca</dc:creator>
    <dc:date>2019-03-10T20:13:13Z</dc:date>
    <item>
      <title>4500X VSS</title>
      <link>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088332#M387286</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A typical Data Center ASA cluster with vPC and VSS(file attached)&lt;/P&gt;
&lt;P&gt;All interfaces and port-channels are up, vPC, VSS, Cluster all OK.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. From Core-S1 Vlan 200 I can reach Vlan 200 on Servers LAN&lt;BR /&gt;2. From Core-S1 Vlan 200 I can reach ip 10.44.124.1 (Vlan124 on Core-S4)&lt;BR /&gt;3. From Core-S1 some traffic to Vlan 124 are ok and some not&lt;BR /&gt;4. From Core-S4 Vlan 124 some traffic to Vlan 124 are ok and some not&lt;BR /&gt;5. If I disable Te1/1/10 and Te1/2/7, vlan 124 is reachable from Core-S1&lt;BR /&gt;6. If I enable Te1/1/10 and Te1/2/7 and disable Te2/1/10 and Te2/2/7, some &lt;BR /&gt;traffic to vlan 124 are ok and some not.&lt;BR /&gt;7. If I move trunk from Core-S1 to Core-S4 with interfaces Te2/1/10 and Te2/2/7 disabled, vlan 124 is reachable.&lt;BR /&gt;&lt;BR /&gt;Do I need special configuration for L3 routing on VSS?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088332#M387286</guid>
      <dc:creator>Eugen Bitca</dc:creator>
      <dc:date>2019-03-10T20:13:13Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088333#M387287</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;What I have seen in the past is that when you connect VSS to a firewall cluster, you can't have cross connects. So, if you remove ports 2/2/7 and 1/1/10 (cross connects) from the VSS switches and just put interface 2/1/10 and 1/2/7 in po3, your design should work fine. &amp;nbsp;Can you test that?&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 15:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088333#M387287</guid>
      <dc:creator>Reza Sharifi</dc:creator>
      <dc:date>2017-08-07T15:32:55Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088334#M387288</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;ASA cluster with cross connects to vPC work great, but to VSS on 4500x not very well.&lt;/P&gt;
&lt;P&gt;To remove cross connects and test I will not be able because I converted 4500X back to standalone.&lt;/P&gt;
&lt;P&gt;I found a link where Cisco do not recommend using this switch for data EtherChannels in Spanned EtherChannel mode due to asymmetric load-balancing(https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#pgfId-137822), so I will not convert them to VSS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How can ASA Cluster (transparent mode) have links to both Core Switches Core-S3 and Core-S4?&lt;/P&gt;
&lt;P&gt;How do you think the following configuration is a good one(file attached)?&lt;/P&gt;
&lt;P&gt;ASA-Cluster&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;interface Port-channel2.124&lt;BR /&gt;&amp;nbsp;vlan 124&lt;BR /&gt;&amp;nbsp;nameif inside124&lt;BR /&gt;&amp;nbsp;bridge-group 1&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel1.324&lt;BR /&gt;&amp;nbsp;vlan 324&lt;BR /&gt;&amp;nbsp;nameif outside324&lt;BR /&gt;&amp;nbsp;bridge-group 1&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel5.524&lt;BR /&gt;&amp;nbsp;vlan 524&lt;BR /&gt;&amp;nbsp;nameif outside524&lt;BR /&gt;&amp;nbsp;bridge-group 1&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;----------------------------------------------------&lt;BR /&gt;Core-S3&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel3&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 124&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;switchport vlan mapping 324 124&lt;BR /&gt;!&lt;BR /&gt;---------------------------------------------------&lt;BR /&gt;Core-S4&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel4&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 124&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;switchport vlan mapping 524 124&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 05:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/4500x-vss/m-p/3088334#M387288</guid>
      <dc:creator>Eugen Bitca</dc:creator>
      <dc:date>2017-08-08T05:25:22Z</dc:date>
    </item>
  </channel>
</rss>

