<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall 4200 Series v7.4.2.1-30; vPC ACI port-channel suspended i in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5288994#M1120950</link>
    <description>&lt;P&gt;Have you by chance looked though through these documents during troubleshooting?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218374-troubleshoot-virtual-port-channel-vpc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218374-troubleshoot-virtual-port-channel-vpc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218194-troubleshoot-aci-vpc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218194-troubleshoot-aci-vpc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope they can point you in the right direction.&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 09:21:07 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2025-05-08T09:21:07Z</dc:date>
    <item>
      <title>Firewall 4200 Series v7.4.2.1-30; vPC ACI port-channel suspended issue</title>
      <link>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5288823#M1120944</link>
      <description>&lt;P&gt;Firewall 4200 Series v7.4.2.1-30; vPC ACI port-channel suspended issue&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Have anyone successfully clustered 4200 Series FTD OS v7.4.2.1-30 on a ACI Leaf switch pair using vPC?&amp;nbsp; I keep getting the switch port suspended causing the FTD cluster to disable the nodes.&amp;nbsp; It does this because before the FTD can complete the clustering, the switch see the FTDs as different port-channel partners.&amp;nbsp; i.e. it doesn't see the cluster as one device yet.&amp;nbsp; As a result, the FTD cluster fails, the switch port channel is suspended.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/cluster/ftd-cluster-sec-fw.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/cluster/ftd-cluster-sec-fw.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have already tried different order of operations without success.&amp;nbsp; I feel this is how it is suppose to work:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure port-channel for cluster control CCL&lt;/LI&gt;
&lt;LI&gt;Configure the cluster adding the cluster control&lt;/LI&gt;
&lt;LI&gt;add, non-configured data cluster node&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Any idea?&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2025 21:26:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5288823#M1120944</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2025-05-07T21:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 4200 Series v7.4.2.1-30; vPC ACI port-channel suspended i</title>
      <link>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5288994#M1120950</link>
      <description>&lt;P&gt;Have you by chance looked though through these documents during troubleshooting?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218374-troubleshoot-virtual-port-channel-vpc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218374-troubleshoot-virtual-port-channel-vpc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218194-troubleshoot-aci-vpc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy-infrastructure-controller-apic/218194-troubleshoot-aci-vpc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope they can point you in the right direction.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 09:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5288994#M1120950</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2025-05-08T09:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 4200 Series v7.4.2.1-30; vPC ACI port-channel suspended i</title>
      <link>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5289422#M1120969</link>
      <description>&lt;P&gt;Hello Marius and thanks.&lt;/P&gt;
&lt;P&gt;I don't think the issue is on the ACI side per se.&amp;nbsp; It seem to be the chicken and egg....which comes first.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;- In order for the ACI switch to enable port-channel, it has to see the partner (FTD) as one device (i.e. the chicken must come first.&amp;nbsp; hahaha..)&lt;/P&gt;
&lt;P&gt;- In order for the FTD to form a cluster, the port-channel has to be up to communicate.&amp;nbsp; (i.e.&amp;nbsp; the egg must come first&amp;nbsp; hahah...)&lt;/P&gt;
&lt;P&gt;Thanks for that info though, but this seems or FTD related.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 12:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5289422#M1120969</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2025-05-09T12:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 4200 Series v7.4.2.1-30; vPC ACI port-channel suspended i</title>
      <link>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5290049#M1120995</link>
      <description>&lt;P&gt;Hi Cisco Community,&lt;/P&gt;
&lt;P&gt;So the resolution is to correctly interpret the Cisco Document below.&amp;nbsp; Hahaha...&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/cluster/ftd-cluster-sec-fw.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/cluster/ftd-cluster-sec-fw.html&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Summary:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The cluster control link (CCL) must use&amp;nbsp;Device-local EtherChannels per FW&lt;/LI&gt;
&lt;LI&gt;The data link, can be Spanned EtherChannels&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;By creating separate etherChannels for each FTD will, obviously, prevent the suspension of the ports on the switch side since it is the same partner (FTD unit).&amp;nbsp; Once the CCL is established, all the FTD unit will appear as one unit on the data link to the switch, which will allow it to be configure as&amp;nbsp;Spanned EtherChannels. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Problem solved.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 18:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-4200-series-v7-4-2-1-30-vpc-aci-port-channel-suspended/m-p/5290049#M1120995</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2025-05-12T18:52:03Z</dc:date>
    </item>
  </channel>
</rss>

