<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDSM EtherChannel Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041628#M78527</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.  The ME6524 has interface vlan256.  It is 10.254.253.13/30.  It has an access port in vlan 256 plugged in to g7/43 on SW2.  G7/43 is an access port in vlan 256.  SW2 has an SVI in interface vlan 255.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup is pretty much the same on SW1.  It has an SVI on vlan 254.  SW1 G7/43 is an access port in vlan 253.  An ME6524 is plugged in to that port on SW1, and it has an SVI on vlan 253 with an access port on vlan 253 plugged in to SW1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ARP table for SW1 shows itself and the ME6524.  The ARP table for SW2 shows itself and 'Incomplete' for the ME6524.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a "packet display" on the IPS unit module 3 in SW2, I see the 6509 ARPs go out looking for the ME6524, but no returns.  I am seeing the ARPs on both interfaces in module 3.  In module 4, I see both the ME6524 and the 6509 sending EIGRP packets to 224.0.0.10, no matter which interface I sniff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Oct 2008 14:35:22 GMT</pubDate>
    <dc:creator>jcrussell</dc:creator>
    <dc:date>2008-10-27T14:35:22Z</dc:date>
    <item>
      <title>IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041620#M78519</link>
      <description>&lt;P&gt;In the config guide for the IDSM, it states:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make sure that the same traffic is assigned to the two data ports on each IDSM-2, you must assign the&lt;/P&gt;&lt;P&gt;same EtherChannel index to both data ports on each of the IDSM-2s even though they are in different&lt;/P&gt;&lt;P&gt;EtherChannel groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me how to change the EtherChannel index?  I have successfully assigned the data ports to a port channel, but I cannot figure out how to change the EtherChannel index.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041620#M78519</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2019-03-10T11:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041621#M78520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 'note' mentioned in the configuration guide is a little misleading. By index they mean interface index of the data port (1 or 2). At least this is my understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;intrusion-detection module 4 data-port 1 channel-group 5&lt;/P&gt;&lt;P&gt;intrusion-detection module 4 data-port 2 channel-group 6&lt;/P&gt;&lt;P&gt;intrusion-detection module 5 data-port 1 channel-group 5&lt;/P&gt;&lt;P&gt;intrusion-detection module 5 data-port 2 channel-group 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They are just telling us not to worry about the 'two' data ports of the IDSM-2 being in TWO different etherchannel groups. We have to make sure that 'first data port' on both IDSM-2 is assigned to the same group and the second data port (data-port 2) is assigned to the same group and not mix it around like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;intrusion-detection module 4 data-port 1 channel-group 6&lt;/P&gt;&lt;P&gt;intrusion-detection module 4 data-port 2 channel-group 5&lt;/P&gt;&lt;P&gt;intrusion-detection module 5 data-port 1 channel-group 5&lt;/P&gt;&lt;P&gt;intrusion-detection module 5 data-port 2 channel-group 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Oct 2008 06:34:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041621#M78520</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-25T06:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041622#M78521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That makes more sense, and that is how I have it configured.  Strangely, one set of IDSM modules is working, and the other is not.  Oh well, I guess I need to take it down another path.  Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Oct 2008 13:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041622#M78521</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-10-25T13:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041623#M78522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you could post your related configuration and topology, maybe me or someone might be able to help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Oct 2008 01:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041623#M78522</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-26T01:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041624#M78523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, sorry about the delay in posting configs.  Here we go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1 contains IDSM units 1 and 2, and is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW2 contains IDSM units 3 and 4, and is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both switches are running Adv Enterprise 12.2(33)SXH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All IDSM are running 6.1(1)E2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1 is peering with an ME6524 over the VLANS I am trying to inspect, and the peering works fine.  SW2 is peering with an ME6524 over the VLANS I am trying to inspect, and the peering keeps going up and down.  CDP shows the neighbor just fine.  Here is the output from the console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW2#&lt;/P&gt;&lt;P&gt;Oct 27 07:52:43.693: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 100: Neighbor 10.254.253.13 (Vlan255) is up: new adjacency&lt;/P&gt;&lt;P&gt;SW2#&lt;/P&gt;&lt;P&gt;Oct 27 07:54:03.204: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 100: Neighbor 10.254.253.13 (Vlan255) is down: Interface Goodbye received&lt;/P&gt;&lt;P&gt;SW2#&lt;/P&gt;&lt;P&gt;Oct 27 07:54:07.484: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 100: Neighbor 10.254.253.13 (Vlan255) is up: new adjacency&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 13:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041624#M78523</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-10-27T13:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041625#M78524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are regular pings working THROUGH this IDSM? (you should employ simple testing before troubleshooting why eigrp is not forming adjacencies).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to post the configuration of the IDSM and the 'show run | inc instrusion' of the host switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 14:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041625#M78524</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-27T14:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041626#M78525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pings are not working through the IDSM on switch number 2.  They do work on switch 1.  I posted the configs of all 4 IDSM units and "sh run | i intru" in the attached zip file in my previous post.  I can repost if it is not working for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 14:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041626#M78525</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-10-27T14:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041627#M78526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw your configurations, seem OK. Can you tell me your setup in more details?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;X &amp;gt;&amp;gt;&amp;gt; VLAN 255 IPS &amp;gt;&amp;gt; VLAN 256 &amp;gt;&amp;gt; Y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is X and Y? what are the IPs? Are the corresponding switchports set to the correct VLAN? Can you see MACs through the IPS (layer 2)? e.g. doing a 'show arp'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 14:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041627#M78526</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-27T14:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041628#M78527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.  The ME6524 has interface vlan256.  It is 10.254.253.13/30.  It has an access port in vlan 256 plugged in to g7/43 on SW2.  G7/43 is an access port in vlan 256.  SW2 has an SVI in interface vlan 255.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup is pretty much the same on SW1.  It has an SVI on vlan 254.  SW1 G7/43 is an access port in vlan 253.  An ME6524 is plugged in to that port on SW1, and it has an SVI on vlan 253 with an access port on vlan 253 plugged in to SW1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ARP table for SW1 shows itself and the ME6524.  The ARP table for SW2 shows itself and 'Incomplete' for the ME6524.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a "packet display" on the IPS unit module 3 in SW2, I see the 6509 ARPs go out looking for the ME6524, but no returns.  I am seeing the ARPs on both interfaces in module 3.  In module 4, I see both the ME6524 and the 6509 sending EIGRP packets to 224.0.0.10, no matter which interface I sniff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 14:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041628#M78527</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-10-27T14:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041629#M78528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend to re-initialize both IDSM in SW2 from scratch and then try. OR As a test you can let go of etherchannel and configure only ONE of them to test things out. I would also recommend to keep the spanning tree settings to the default and not change the cost etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 19:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041629#M78528</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-27T19:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041630#M78529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I completely blew away the configs and reconfigured, and it is working now.  Not sure what it was, because I just copied and pasted the configs back in!  Anyway, thanks for your help happs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 20:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041630#M78529</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-10-27T20:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041631#M78530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm glad its working now :). And thanks to Microsoft for teaching us the 'restart and fix' technique :).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2008 05:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041631#M78530</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-10-28T05:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041632#M78531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, it looks like I spoke too soon.  Once I took the IDSMs out of bypass mode, they will not pass TACACS traffic.  Other traffic will pass, but I cannot get my switches to talk to the ACS box.  I can ping, SSH, RDP, etc but no TACACS.  Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 02:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041632#M78531</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-11-01T02:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041633#M78532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TACACS stops working once the IPS stops inspecting or when it is in bypass mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are some TCP normalizaion signatures that have a 'Deny' action by default, maybe they are denying this trafic. You can either remove the deny action from all those signatures (using a few clicks only) or make an event action filter for this particular client/server flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 13:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041633#M78532</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-11-01T13:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041634#M78533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It stops working when I take the IPS out of bypass mode and have it inspect traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try an event action filter and see what happens.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, another update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears that in the second switch with IPS 3 and IPS 4, the traffic is not taking the same path as it does in switch 1.  In switch 1, traffic between 2 certain hosts uses just IPS 1, like I would expect.  In switch 2, I see traffic between 2 certain hosts going through IPS 3 in one direction, and IPS 4 in the other.  So that leads me to think there is something wrong with the EtherChannel load balancing.  Thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2008 14:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041634#M78533</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-11-03T14:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041635#M78534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Technically the same source/dest pair should be served by the same IPS if the network has everything configured properly. It seems you have assymetric routing, can you post the output of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show etherchannel load-balance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2008 10:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041635#M78534</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-11-04T10:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041636#M78535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SW1 (the one that seems to be load balancing properly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#sh etherchannel load-balance &lt;/P&gt;&lt;P&gt;EtherChannel Load-Balancing Configuration:&lt;/P&gt;&lt;P&gt;        src-dst-ip enhanced&lt;/P&gt;&lt;P&gt;        mpls label-ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EtherChannel Load-Balancing Addresses Used Per-Protocol:&lt;/P&gt;&lt;P&gt;Non-IP: Source XOR Destination MAC address&lt;/P&gt;&lt;P&gt;  IPv4: Source XOR Destination IP address&lt;/P&gt;&lt;P&gt;  IPv6: Source XOR Destination IP address&lt;/P&gt;&lt;P&gt;  MPLS: Label or IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW2 (the one that seems to not be load balancing properly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW2#sh etherchannel load-balance &lt;/P&gt;&lt;P&gt;EtherChannel Load-Balancing Configuration:&lt;/P&gt;&lt;P&gt;        src-dst-ip enhanced&lt;/P&gt;&lt;P&gt;        mpls label-ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EtherChannel Load-Balancing Addresses Used Per-Protocol:&lt;/P&gt;&lt;P&gt;Non-IP: Source XOR Destination MAC address&lt;/P&gt;&lt;P&gt;  IPv4: Source XOR Destination IP address&lt;/P&gt;&lt;P&gt;  IPv6: Source XOR Destination IP address&lt;/P&gt;&lt;P&gt;  MPLS: Label or IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2008 13:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041636#M78535</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-11-04T13:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041637#M78536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are you inline normalizer settings in the virtual sensor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2008 15:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041637#M78536</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-11-04T15:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041638#M78537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My Inline TCP Session Tracking Mode is Interface and VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Normalizer Mode is Strict Evasion Protection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You think the Normalizer should be in Asymmetric Mode Protection?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2008 15:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041638#M78537</guid>
      <dc:creator>jcrussell</dc:creator>
      <dc:date>2008-11-04T15:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM EtherChannel Question</title>
      <link>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041639#M78538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes that would be worth a try (At least to test if it does the trick).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2008 02:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-etherchannel-question/m-p/1041639#M78538</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-11-05T02:55:01Z</dc:date>
    </item>
  </channel>
</rss>

