<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High Availability Setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181184#M1075639</link>
    <description>&lt;P&gt;I would love to hire a consultant.&amp;nbsp; We just can't afford it.&amp;nbsp; I am making progress I think.&amp;nbsp; I created sub-interfaces on one of the ports and I created a port-channel on the switch and it looks like I am getting some kind of connection.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 22:04:49 GMT</pubDate>
    <dc:creator>gcook0001</dc:creator>
    <dc:date>2020-11-09T22:04:49Z</dc:date>
    <item>
      <title>High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181109#M1075631</link>
      <description>&lt;P&gt;I have been doing a lot of reading but I haven't found what I am looking for.&amp;nbsp; &amp;nbsp;We recently purchased two Firepower 1140's to replace our Meraki appliances.&amp;nbsp; &amp;nbsp;We have two Catalyst 3850 switches in a non-stacked configuration.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to setup them up using the following but I can't find any documentation that I can follow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FP1 - port 1 to ISP&lt;/P&gt;&lt;P&gt;FP1 - port 3 to 3850-1 carrying vlans 3,4,5,6 (port-channel 1)&lt;/P&gt;&lt;P&gt;FP1 - port 4 to 3850-1 carrying vlans 3,4,5,6 (port-channel 1)&lt;/P&gt;&lt;P&gt;FP1 - port 5 to 3850-2&amp;nbsp;carrying vlans 3,4,5,6 (port-channel 2)&lt;/P&gt;&lt;P&gt;FP1 - port 6 to 3850-2&amp;nbsp;carrying vlans 3,4,5,6 (port-channel 2)&lt;/P&gt;&lt;P&gt;FP1 - port 8 to FP2 - port 8 - failover link&lt;/P&gt;&lt;P&gt;FP2 - port 1 to ISP&lt;/P&gt;&lt;P&gt;FP2 - port 3 to 3850-1 carrying vlans 3,4,5,6 (port-channel 3)&lt;/P&gt;&lt;P&gt;FP2 - port 4 to 3850-1 carrying vlans 3,4,5,6 (port-channel 3)&lt;/P&gt;&lt;P&gt;FP2 - port 5 to 3850-2&amp;nbsp;carrying vlans 3,4,5,6 (port-channel 4)&lt;/P&gt;&lt;P&gt;FP2 - port 6 to 3850-2&amp;nbsp;carrying vlans 3,4,5,6 (port-channel 4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently have&lt;/P&gt;&lt;P&gt;3850-1 to 3850-2 port-channel 20 carrying vlans 3,4,5,6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone could point me to some decent documentation on doing this it would be great.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 19:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181109#M1075631</guid>
      <dc:creator>gcook0001</dc:creator>
      <dc:date>2020-11-09T19:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181115#M1075632</link>
      <description>&lt;P&gt;why not follow the below guide what is recommended for the HA environment, what is not recommended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have 2 ISP is thei active failover you like to both the ISP ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/fdm/fptd-fdm-config-guide-630/fptd-fdm-ha.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/630/fdm/fptd-fdm-config-guide-630/fptd-fdm-ha.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;read the above document, make a small network diagram which gives you a clear picture and understands what you looking do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;still have questions post the high-level diagram of your network so we can look and suggest what suitable approach you can take.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 20:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181115#M1075632</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-09T20:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181138#M1075634</link>
      <description>&lt;P&gt;Thanks for the quick reply.&lt;/P&gt;&lt;P&gt;I read both those documents previously.&amp;nbsp; What is missing is how to create port-channels carrying multiple vlans/subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I attached a document showing the layout.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 20:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181138#M1075634</guid>
      <dc:creator>gcook0001</dc:creator>
      <dc:date>2020-11-09T20:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181141#M1075635</link>
      <description>&lt;P&gt;the best approach is FW on a stick with Port-channel with sub-interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;each FW go with respected Parent switch port-channel and dedicated interface for HA sync link if they are in same location.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terminated your ISP into Switch with a different VLAN segment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 20:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181141#M1075635</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-09T20:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181149#M1075637</link>
      <description>&lt;P&gt;OK.&amp;nbsp; I have no idea what you said.&amp;nbsp; I the firewalls setup as in the diagram.&amp;nbsp; I just can't figure out how to handle the different vlan/subnets between the switch and the firewalls.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 21:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181149#M1075637</guid>
      <dc:creator>gcook0001</dc:creator>
      <dc:date>2020-11-09T21:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181153#M1075638</link>
      <description>&lt;P&gt;here is a high level, if you still not sure, suggest hiring a consultant, rather make it difficult to make it,&amp;nbsp; and eventually you can learn from them so you can maintain the network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="highlevel.JPG" style="width: 945px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/88076i3E771F927C5B6571/image-size/large?v=v2&amp;amp;px=999" role="button" title="highlevel.JPG" alt="highlevel.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 21:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181153#M1075638</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-09T21:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181184#M1075639</link>
      <description>&lt;P&gt;I would love to hire a consultant.&amp;nbsp; We just can't afford it.&amp;nbsp; I am making progress I think.&amp;nbsp; I created sub-interfaces on one of the ports and I created a port-channel on the switch and it looks like I am getting some kind of connection.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 22:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181184#M1075639</guid>
      <dc:creator>gcook0001</dc:creator>
      <dc:date>2020-11-09T22:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: High Availability Setup</title>
      <link>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181870#M1075660</link>
      <description>&lt;P&gt;So there is no documentation on how to implement this design.&amp;nbsp; &amp;nbsp;I have worked with two other firewall vendors previously and there was always a couple of default senarios that were well documented.&amp;nbsp; I have looked everyone on the Cisco site and I don't find anything.&amp;nbsp; &amp;nbsp;I must not be the first person to want to use their firewalls for handling traffic between multiple VLANs.&amp;nbsp; I am not asking for someone to design this for me, I am asking for clear documentation that explains how to do this.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 22:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-availability-setup/m-p/4181870#M1075660</guid>
      <dc:creator>gcook0001</dc:creator>
      <dc:date>2020-11-10T22:07:02Z</dc:date>
    </item>
  </channel>
</rss>

