날짜: 12-26-2024 08:08 PM
You used BVI on the router to bundle two interfaces into one interface, and now you need to configure them as one network using portchannel on the ASAv.
However, the ASAv must function as a failover.
Below is the topology and the configuration of the routers.
interface GigabitEthernet0/2
no ip address
duplex auto
speed auto
media-type rj45
bridge-group 1
!
interface GigabitEthernet0/4
no ip address
shutdown
duplex auto
speed auto
media-type rj45
bridge-group 1
!
interface BVI1
ip address 114.141.24.1 255.255.255.252
!
해결되었습니다! 솔루션으로 이동.
12-26-2024 09:22 PM - 편집 12-26-2024 09:32 PM
You can NOT config it as PO since the FW is HA active/standby
this only work for FW cluster
MHM
날짜: 12-26-2024 08:21 PM
Sorry what is Q here.
MHM
날짜: 12-26-2024 09:15 PM
PUB-R2's interfaces g0/2 and g0/4 are grouped together as BVI to make them a single interface.
On the other side, we want to group G0/0 of FW1 and 2 into one interface.
12-26-2024 09:22 PM - 편집 12-26-2024 09:32 PM
You can NOT config it as PO since the FW is HA active/standby
this only work for FW cluster
MHM
날짜: 12-27-2024 08:57 AM
That's not possible
날짜: 12-26-2024 09:20 PM
"If you use the ASA device in an Active/Standby failover deployment, then you need to create separate EtherChannels on the switches in the VSS/vPC, one for each ASA device. On each ASA deivce, a single EtherChannel connects to both switches. Even if you could group all switch interfaces into a single EtherChannel connecting to both ASA devices (in this case, the EtherChannel will not be established because of the separate ASA system IDs), a single EtherChannel would not be desirable because you do not want traffic sent to the standby ASA device. "
Here what Cisco says. You should not add a port-channel on both active and standby firewall because the traffic will be load balanced between them and you should not receive traffic on the firewall in standby mode.
새로운 아이디어를 발견하고 저장하세요. 전문가 답변, 단계별 가이드, 최근 주제 등 다양한 내용을 확인해 보세요.
처음이신가요? 아래 팁들을 확인해 보세요. 시스코 커뮤니티 사용하기 새 멤버 가이드