<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD HA Pair Using Several Thousand MAC Addresses in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620026#M1090478</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The iBGP link is done through dedicated east-west interfaces on the ASRs, so that traffic never makes it to the L2 2960 stack. &amp;nbsp;What’s odd is, all of the “extra” MAC addresses are showing up on the interface facing the active Firepower, not the ASRs. &amp;nbsp;Also, this doesn’t happen all of the time. &amp;nbsp;For instance, it’s been 24 hours since I deleted the “administratively down” etherchannel in FXOS, and we have not had any issues. &amp;nbsp;But I could happen again tomorrow. &amp;nbsp;Sometimes it will be hours or a day before it happens again. My fingers are crossed that it’s some strange bug in FXOS and deleting that etherchannel fixed it. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 May 2022 01:53:13 GMT</pubDate>
    <dc:creator>Mike Wagner</dc:creator>
    <dc:date>2022-05-30T01:53:13Z</dc:date>
    <item>
      <title>FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619740#M1090466</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Posting here in a last ditch effort.&amp;nbsp; Any help is greatly appreciated.&amp;nbsp; Cisco TAC, despite the hefty fee we pay, is very unresponsive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two Firepower 4110 units in an HA Active/Standby cluster.&amp;nbsp; The "outside" interfaces of these two FTD boxes are connected to a 2960-X switch stack on an L2 VLAN, as are our two edge ASR 1002-X router "inside" interfaces.&amp;nbsp; This is due to not having enough 10Gb ports on the ASR's to connect both FTD's to each ASR.&amp;nbsp; The ASR's are in HSRP mode and iBGP is configured for our backup connection to kick in whenever the main goes down.&amp;nbsp; The scenario is fully redundant, and has worked for over 6 months.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently the outside interface of the FTD HA pair has become unresponsive randomly.&amp;nbsp; The only way I could make the FTD pair outside interface to become responsive is by rebooting the 2960-X switch stack, or flipping the active/standby units on the HA pair.&amp;nbsp; Since it's Saturday and there aren't many people in, I was able to delve into this much further since it happened again this morning...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I found is that the 2960-X stack is showing over 8k MAC addresses on the port that the active FTD unit is plugged into.&amp;nbsp; It should only be one (that of the active outside interface on the HA pair), as it's an L3 interface on the FTD side.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like I said, this issue comes and goes, so I rebooted the switch stack, and we're back down to the normal amount of MAC addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a wild theory, but I never did setup active/standby MACs on the HA Pair when I created it.&amp;nbsp; Everything I read indicates this should not be a problem.&amp;nbsp; However, I decided to go ahead and set them up now as a last ditch effort.&amp;nbsp; As soon as I created them and hit deploy, the deployment hung up at 20% for a very long time.&amp;nbsp; I then used OmniQuery to remove the deploy.&amp;nbsp; I rebooted the FTD's and FMC.&amp;nbsp; Unfortunately, even though OmniQuery shows no more status 7 tasks, the task is still showing in FMC as In Progress... (%)&amp;nbsp; - No Number for the percent!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas are greatly appreciated!&amp;nbsp; I'm at my wits end.!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 19:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619740#M1090466</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-28T19:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619751#M1090467</link>
      <description>&lt;P&gt;Can you draw topology&amp;nbsp;&lt;BR /&gt;ASR is connect to FTD I confuse on this point.&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 21:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619751#M1090467</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-28T21:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619754#M1090468</link>
      <description>&lt;P&gt;Sorry for the quick and dirty redacting and screen capture of the attached network drawing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is two of everything, and each ASR and each FTD are connected to 10Gb ports in a 2960 stack (cheapest way I could get a switch with 4 10gb ports at the time)... to create a big L2 domain between edge ASRs and edge FTDs.&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 21:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619754#M1090468</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-28T21:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619767#M1090469</link>
      <description>&lt;P&gt;one more Q. are you config BD in FTD ?&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 23:25:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619767#M1090469</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-28T23:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619771#M1090470</link>
      <description>&lt;P&gt;Sorry for my ignorance. &amp;nbsp;What do you mean by BD?&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 00:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619771#M1090470</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-29T00:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619772#M1090471</link>
      <description>&lt;P&gt;bridge domain&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 00:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619772#M1090471</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-29T00:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619776#M1090472</link>
      <description>&lt;P&gt;Interesting... That definitely would explain some things.&lt;/P&gt;&lt;P&gt;I checked in FMC, and did not find any bridge groups.&amp;nbsp; I did, however, check the the FXOS configurations themselves, and found an administratively down cluster etherchannel interface.&amp;nbsp; It's down, so unless there's some strange bug it shouldn't be causing the issue.&amp;nbsp; However, I've deleted it just in case.&amp;nbsp; Maybe that is the culprit?&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 01:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619776#M1090472</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-29T01:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619784#M1090473</link>
      <description>&lt;P&gt;one more Q are ASR is run BGP with ISP?&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 02:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619784#M1090473</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-29T02:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619787#M1090474</link>
      <description>&lt;P&gt;The ASR’s are indeed BGP peering with the ISP equipment. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 03:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619787#M1090474</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-29T03:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619816#M1090475</link>
      <description>&lt;P&gt;How many instane are running on FTD 4100? what is the version you on FXOS and what version is the FTD on the chassis and what version you running on FMC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What I found is that the 2960-X stack is showing over 8k MAC addresses on the port that the active FTD unit is plugged into. It should only be one (that of the active outside interface on the HA pair), as it's an L3 interface on the FTD side.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you issue command show logging on the swtich and see what logs it display. Is your L2 is consistant? I mean on STP issues anywhere? you can check "&lt;SPAN&gt;&lt;EM&gt;show spanning&lt;/EM&gt;-&lt;EM&gt;tree detail&lt;/EM&gt; | in &lt;EM&gt;ieee&lt;/EM&gt;|from|&lt;EM&gt;occur&lt;/EM&gt;|is &lt;EM&gt;exec&lt;/EM&gt;&lt;/SPAN&gt;".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once you failed over the HA pair everything start working fine. it could be a issue some where in Layer2 (My guess). whats change happen in this network since last six months?&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 08:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4619816#M1090475</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-05-29T08:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620009#M1090476</link>
      <description>&lt;P&gt;Nothing has changed on the L2 side, and nothing in logging &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;only thing is, about a month ago we had to cut power to the datacenter. &amp;nbsp;Maybe something did not come back up right. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;not sure on FXOS version, will let you know. &amp;nbsp;FTD version 7.0.1-82. &amp;nbsp;Previously on 6.6 and it was doing it then. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;one instance on each 4110&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 23:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620009#M1090476</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-29T23:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620010#M1090477</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;and Me suspect that this issue relate some how to L2,&lt;BR /&gt;but 8K MAC&amp;lt;&amp;lt;&amp;lt;&amp;lt; this to huge mac address,&amp;nbsp;&lt;BR /&gt;you mention that there is DC, and I see iBGP&lt;BR /&gt;SO here the Q,&lt;BR /&gt;are you config any L2VPN (L2 over MPLS)??&lt;BR /&gt;I think that L2VPN and there is iBGP interconnect both Edge router ASR through SW is cause this huge Number of Mac address.&lt;BR /&gt;&lt;BR /&gt;check the BGP L2VPN&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 23:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620010#M1090477</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-29T23:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620026#M1090478</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The iBGP link is done through dedicated east-west interfaces on the ASRs, so that traffic never makes it to the L2 2960 stack. &amp;nbsp;What’s odd is, all of the “extra” MAC addresses are showing up on the interface facing the active Firepower, not the ASRs. &amp;nbsp;Also, this doesn’t happen all of the time. &amp;nbsp;For instance, it’s been 24 hours since I deleted the “administratively down” etherchannel in FXOS, and we have not had any issues. &amp;nbsp;But I could happen again tomorrow. &amp;nbsp;Sometimes it will be hours or a day before it happens again. My fingers are crossed that it’s some strange bug in FXOS and deleting that etherchannel fixed it. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 01:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620026#M1090478</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-30T01:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620641#M1090494</link>
      <description>&lt;P&gt;but you don't answer me are you use any L2VPN ?&lt;BR /&gt;if yes then stare the output of show bgp,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;8K MAC address for your network is too high number, but if there is L2VPN then this DC have MAC address for all user in all site,&amp;nbsp;&lt;BR /&gt;keep in mind that the BGP can carry MAC address and use it to exchange L2 traffic between the DC and other site.&amp;nbsp;&lt;BR /&gt;for some reason the FTD is in way and show this huge number of MAC address.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 15:25:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620641#M1090494</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-30T15:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620681#M1090495</link>
      <description>&lt;P&gt;I understand what you’re saying, however there is no L2VPN in use at all. &amp;nbsp;All of this, the dual devices and everything, is contained within one single datacenter. &amp;nbsp;Our outside BGP peers are with our carrier on a government network. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 16:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620681#M1090495</guid>
      <dc:creator>Mike Wagner</dc:creator>
      <dc:date>2022-05-30T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA Pair Using Several Thousand MAC Addresses</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620753#M1090501</link>
      <description>&lt;P&gt;The best course of action would be work with Cisco TAC as you already mentioned you opened case with Cisco. If you not happy with your TAC Engineer you can always request for change of Engineer or even you could request a Senior TAC Engineer. Once you make this request Cisco TAC can not deny you to put you though to senior Netowrk Engineer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as we do not have much information on few bits of detial. personally, I would recommand to work with TAC and get this sorted the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 18:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-using-several-thousand-mac-addresses/m-p/4620753#M1090501</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-05-30T18:33:18Z</dc:date>
    </item>
  </channel>
</rss>

