cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
852
Views
5
Helpful
3
Replies

GSS to CSS, convert ICMP keepalive to shared KAL-AP

wilson_1234_2
Level 3
Level 3

After modifying the keeplive on the GSS answer file to the shared KAL-AP, does the GSS still need to get to the IP Address of the ICMP keepalive?


For example, currently the GSS is pinging each individual address configured in each Answer entry.

Do I still need to have connectivity from the GSS to each of these these addresses, or is the status
information for all Answer files provided in the single KAL-AP session from the GSS to the interface on the CSS?

If so then,

We have three GSS devices
GSSM - Primary
GSS
GSSM - Secondary

The secondary GSSM is in our DR site in another part of the country.

We need to make sure all three GSSs can get to the IP Address of the CSS interface configured in the KAL-AP Session, correct?

3 Replies 3

ohynderi
Level 1
Level 1

Hi,

With KAL-AP Keepalive, GSS only needs connectivity to the primary / secondary ip address configured. Those IP's are used to setup the CAPP session. There is no need for GSS to have connectivity to the answers ip.

Generally speaking, with shared keepalive, GSS needs to have connectivity to the keepalive and not the answer ip. Same if you configure a (none shared) keepalive with a different ip address than the vip address.

I hope it helps,

Olivier

Thanks

In our current scenario, the GSSM Primary and the GSS are in the Main site and the GSSM Secondary is in a DR site.

I wouldnt think the shared keepalive traffic should go across the Internet as it is from GSS to CSS.

If I wanted to ensure that when the DR site Internet is down, that we do not send DNS requests to anything in that site, if the keepalive traffic is internal, how do we make sure nothing gets sent to that site?

Would the inter GSS communication traffic be sent across the Internet?

Every GSS (including primary and standby GGSM) sends keepalive individually to the Answers. So, if connectivity between main and DR site is internet, then indeed, primary GGSM and GSS will send keepalives over Internet to the DR. Same for inter GSS communication traffic.

The GSSs will stop responding with DR IP's, if corresponding keepalive have failed. That depends on how you configured it. Maybe best would that put out of service one of the VIP in the DR. Check then if GSS detect it properly.

Olivier

Review Cisco Networking for a $25 gift card