<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA , 3750 Switch stack ,Etherchanel cross-stack and HA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-3750-switch-stack-etherchanel-cross-stack-and-ha/m-p/2492164#M268965</link>
    <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I have run into a scenario where there they use a switch stack of four 3750’s and two ASA 5540 in Active-stanby HA Pair.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;ASA's are connected with 4 interfaces across stack (1 interface to each switch).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;1 Etherchannels (4 ports) is configured between ASA and switch. All vlans are terminated on ASA as a subiterfaces.&lt;/P&gt;&lt;P&gt;somehting like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port-channell1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Port-channell1.10&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;vlan 10&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;ip address 192.168.10.1 255.255.255.0 stanby 192.168.10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port-channell1.20&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;vlan 10&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;ip address 192.168.20.1 255.255.255.0 stanby 192.168.20.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;..and so on..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;There is about different 60-70 vlans currently terminated on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;We found a problem with failover testing:&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;When we test the failover and fail manually with “failover active” command, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;It looks like only 29 vlans can fail to backup ASA instantly , the rest can take up to 5 min.&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Is there a limitation for ASA or 3750 etherchannel&amp;nbsp; in this scenario why it would not failover instantly for all vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Thanks&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Martin&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:51:06 GMT</pubDate>
    <dc:creator>bufycisco77</dc:creator>
    <dc:date>2019-03-12T03:51:06Z</dc:date>
    <item>
      <title>ASA , 3750 Switch stack ,Etherchanel cross-stack and HA</title>
      <link>https://community.cisco.com/t5/network-security/asa-3750-switch-stack-etherchanel-cross-stack-and-ha/m-p/2492164#M268965</link>
      <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I have run into a scenario where there they use a switch stack of four 3750’s and two ASA 5540 in Active-stanby HA Pair.&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;ASA's are connected with 4 interfaces across stack (1 interface to each switch).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;1 Etherchannels (4 ports) is configured between ASA and switch. All vlans are terminated on ASA as a subiterfaces.&lt;/P&gt;&lt;P&gt;somehting like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port-channell1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Port-channell1.10&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;vlan 10&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;ip address 192.168.10.1 255.255.255.0 stanby 192.168.10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port-channell1.20&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;vlan 10&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;ip address 192.168.20.1 255.255.255.0 stanby 192.168.20.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;..and so on..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;There is about different 60-70 vlans currently terminated on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;We found a problem with failover testing:&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;When we test the failover and fail manually with “failover active” command, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;It looks like only 29 vlans can fail to backup ASA instantly , the rest can take up to 5 min.&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Is there a limitation for ASA or 3750 etherchannel&amp;nbsp; in this scenario why it would not failover instantly for all vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Thanks&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Martin&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-3750-switch-stack-etherchanel-cross-stack-and-ha/m-p/2492164#M268965</guid>
      <dc:creator>bufycisco77</dc:creator>
      <dc:date>2019-03-12T03:51:06Z</dc:date>
    </item>
    <item>
      <title>ASA , 3750 Switch stack ,Etherchanel cross-stack and HA</title>
      <link>https://community.cisco.com/t5/network-security/asa-3750-switch-stack-etherchanel-cross-stack-and-ha/m-p/2492165#M268966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sory mistake there :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Port-channell1.20&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0cm 0cm 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;vlan 20&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0cm 0cm 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;ip address 192.168.20.1 255.255.255.0 stanby 192.168.20.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0cm 0cm 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 13:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-3750-switch-stack-etherchanel-cross-stack-and-ha/m-p/2492165#M268966</guid>
      <dc:creator>bufycisco77</dc:creator>
      <dc:date>2014-02-27T13:49:22Z</dc:date>
    </item>
  </channel>
</rss>

