<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Marvin,Based on the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444644#M238324</link>
    <description>&lt;P&gt;Thanks Marvin,&lt;/P&gt;&lt;P&gt;Based on the Cisco TAC Podcast, I was afraid I would need a 10Gbps CCL link but appears now I am good with a 1 Gbps link (for now) until my throughput requirements increase. Excellent.&lt;/P&gt;&lt;P&gt;Thank you again for the quick responses, appreciate your support!&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2014 13:54:45 GMT</pubDate>
    <dc:creator>fsebera</dc:creator>
    <dc:date>2014-05-21T13:54:45Z</dc:date>
    <item>
      <title>ASA CCL cluster link requirment</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444640#M238320</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;We have 2 geographic dispersed sites with 500Mbps throughput Internet access on both. We currently have 1 ASA 5585-x firewall at each site. We would like to enable clustering between the firewalls.&lt;/P&gt;&lt;P&gt;Is the Cluster Control Link (CCL) requirement 10Gbps and 10ms latency or less (20ms round trip)&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;is this a highly recommended suggestion.&lt;/P&gt;&lt;P&gt;And if this is a recommendation and we only have 500Mbps internet throughput, could we get away with CCL being something less than 10Gbps?&lt;/P&gt;&lt;P&gt;Suggestions please!!&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444640#M238320</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2019-03-12T04:13:31Z</dc:date>
    </item>
    <item>
      <title>The 10 ms latency is a hard</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444641#M238321</link>
      <description>&lt;P&gt;The 10 ms latency is a hard requirement and requires 9.1(4). The bandwidth is not mandatory but it must match the maximum forwarding capacity of each member.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer to Cisco Live! presentation BRKSEC-3032, slide 26.&lt;/P&gt;&lt;P&gt;I would assume you have dome sort of interconnect between your outside switches as well as the cluster members all have outside interfaces addressed from a single pool.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 13:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444641#M238321</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-21T13:24:26Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,Excellent, Our</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444642#M238322</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Excellent, Our current link latency 1-way is 6ms and IOS version can/will be upgraded!&lt;/P&gt;&lt;P&gt;Cisco Live! presentation - would/could you provide a link -PLEASE.&lt;/P&gt;&lt;P&gt;Inside and outside connectivity is good too; simple 3750-x stacks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 question:&lt;/P&gt;&lt;P&gt;If our internet links are 500Mbps each, x2 = 1Gbps, does this mean the CCL should be at least 1Gbps or better?&lt;/P&gt;&lt;P&gt;Our internal (inside) links are 1 Gbps links but due to the Internet bottle neck are automatically slowed to 500Mbps too.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 13:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444642#M238322</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2014-05-21T13:33:08Z</dc:date>
    </item>
    <item>
      <title>The presentation is here.</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444643#M238323</link>
      <description>&lt;P&gt;The presentation is &lt;A href="https://www.ciscolive2014.com/connect/sessionDetail.ww?SESSION_ID=2205"&gt;here&lt;/A&gt;. There are also a number of slides on different inter-DC clustering scenarios and differences between 9.1 and 9.2 in that regard.&lt;/P&gt;&lt;P&gt;You may need to setup a (free) Cisco Live 365 userid (separate from cisco.com ID) to be able to access and download the slides.&lt;/P&gt;&lt;P&gt;While I suppose the CCL could technically be 500 Mbps, the practical amount would be 1 Gbps as it needs to be a dedicated link (not shared with any other service).&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 13:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444643#M238323</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-21T13:54:44Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin,Based on the</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444644#M238324</link>
      <description>&lt;P&gt;Thanks Marvin,&lt;/P&gt;&lt;P&gt;Based on the Cisco TAC Podcast, I was afraid I would need a 10Gbps CCL link but appears now I am good with a 1 Gbps link (for now) until my throughput requirements increase. Excellent.&lt;/P&gt;&lt;P&gt;Thank you again for the quick responses, appreciate your support!&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 13:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444644#M238324</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2014-05-21T13:54:45Z</dc:date>
    </item>
    <item>
      <title>You're welcome, thanks for</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444645#M238325</link>
      <description>&lt;P&gt;You're welcome, thanks for the rating.&lt;/P&gt;&lt;P&gt;I would not generally contradict anything the guys on the TAC Security Podcast say - that's an excellent resource. I've learned a lot listening to them.&lt;/P&gt;&lt;P&gt;I believe, however, in this case they were assuming that any 5585-X cluster would be using the the bandwidth of one (or more) 10 Gbps interface for their production traffic. In that case, you definitely would not want the CCL to be 1 Gbps.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 14:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444645#M238325</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-21T14:17:31Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444646#M238326</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;I have a query related to CCL Link.&lt;/P&gt;
&lt;P&gt;Is the CCL links are encrypted by default? if Yes, is it SSL?&lt;/P&gt;
&lt;P&gt;Or do we need to enable any command to do the encryption?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Jacob&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 13:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444646#M238326</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2016-09-28T13:05:17Z</dc:date>
    </item>
    <item>
      <title>Jacob,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444647#M238327</link>
      <description>&lt;P&gt;Jacob,&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: line-through;"&gt;I do not believe ASA Cluster Control Links have any encryption - either by default or as an option.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Update - correct answer provided by Aditya.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 05:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444647#M238327</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-29T05:35:04Z</dc:date>
    </item>
    <item>
      <title>Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444648#M238328</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;
&lt;P&gt;Thanks for your update. I am a bit confused, below is a quote from a Cisco LLD document provided to my customer&amp;nbsp;by Cisco Advanced Services.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;New cluster members must use the same &lt;STRONG&gt;SSL encryption&lt;/STRONG&gt; setting (the ssl encryption command) as the master unit for initial cluster control link communication before configuration replication."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;But I didn't see any config related to encryption in the config provided in NIP Document, that's why I asked is it enabled by default or not.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;This quote from Cisco Live Doc attached&amp;nbsp;also mentioned (Page 37 Preparation Check List)&amp;nbsp;something related to encryption, but still not clear.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;All cluster members must have matching &lt;STRONG&gt;3DES&lt;/STRONG&gt; and 10GE I/O licenses"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT size="2"&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT size="2"&gt;Appreciate if you could help.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT size="2"&gt;t&lt;/FONT&gt;&lt;/EM&gt;&lt;EM&gt;&lt;FONT size="2"&gt;hanks&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Jacob&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;FONT size="5"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 05:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444648#M238328</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2016-09-29T05:35:05Z</dc:date>
    </item>
    <item>
      <title>Hi Jacob,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444649#M238329</link>
      <description>&lt;P&gt;Hi Jacob,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes CCL uses SSL encryption for communication to the slave members and if the licenses and SSL encryption is not same it would fail to form a cluster.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check this link for more info:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/en/US/products/ps12726/products_tech_note09186a0080c03900.shtml&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 06:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444649#M238329</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-09-29T06:07:25Z</dc:date>
    </item>
    <item>
      <title>@Aditya Ganjoo  ,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444650#M238330</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/adganjoo"&gt;adganjoo&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;I stand corrected. Thanks for the update.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edited my earlier reply.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 15:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ccl-cluster-link-requirment/m-p/2444650#M238330</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-29T15:14:22Z</dc:date>
    </item>
  </channel>
</rss>

