06-27-2019 12:05 AM
Hi,
Our IT guy has designed a network layout that I am not sure about after reading the cisco guides.
We have a single ASA5516X connected to a switch stack of 2 3650's.
He has the ASA connected to the switch stack via dual port etherchannel, but I have read the below form the guides:-
The ASA does not support connecting an EtherChannel to a switch stack. If the ASA EtherChannel is connected cross stack, and if the Master switch is powered down, then the EtherChannel connected to the remaining switch will not come up.
IF this is the case, what is the best way to connect the ASA to the switches so that if one goes down the other stays running?
Just a warning, I am not very good on cisco's, only ever used fortinets before, so if the terminology is wrong, I apologise.
Solved! Go to Solution.
06-27-2019 12:47 AM
Hi Mark,
Looking at the following doc below you are correct. I guess if this is something you had to do then there are some suggestions below from Cisco in that document if you still want to use Etherchannel. You could maybe look at redundant interfaces, also referenced in the doc.
It states -
In Cisco IOS software versions earlier than 15.1(1)S2, the ASA did not support connecting an
EtherChannel to a switch stack. With default switch settings, if the ASA EtherChannel is connected cross
stack, and if the master switch is powered down, then the EtherChannel connected to the remaining
switch will not come up. To improve compatibility, set the stack-mac persistent timer command to a
large enough value to account for reload time; for example, 8 minutes or 0 for indefinite. Or, you can
upgrade to more a more stable switch software version, such as 15.1(1)S2.
06-27-2019 12:47 AM
Hi Mark,
Looking at the following doc below you are correct. I guess if this is something you had to do then there are some suggestions below from Cisco in that document if you still want to use Etherchannel. You could maybe look at redundant interfaces, also referenced in the doc.
It states -
In Cisco IOS software versions earlier than 15.1(1)S2, the ASA did not support connecting an
EtherChannel to a switch stack. With default switch settings, if the ASA EtherChannel is connected cross
stack, and if the master switch is powered down, then the EtherChannel connected to the remaining
switch will not come up. To improve compatibility, set the stack-mac persistent timer command to a
large enough value to account for reload time; for example, 8 minutes or 0 for indefinite. Or, you can
upgrade to more a more stable switch software version, such as 15.1(1)S2.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide