cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
231
Views
0
Helpful
1
Replies

Conflict between LACP timeout and LACP cost

Yoshimine
Level 1
Level 1

Hi everyone, im facing some issue in my configuration all 4 gears are Cisco Firepower 2130, and they are in HA mode, the top two is located in Site A  and bottom two are located on Site B, the original configuration does not include port 15 and port 16, only was port 11 and was working without problems, on fail event on active firewall (LEFT), the standby (RIGHT) assumes the network traffic between sites. Recently we are facing some intervantions from our IT without any previous warning, and after too much fight they installed to our application  dedicated fibers direct connected to our appliance, so in Firepower Management i have created the etherchannel and that works flawless, and we keep the IT network link as bakup, the configuration between the two sites its a simple OSPF, so to force the traffic between sites in the dedicated link, i just added a cost to the IT network on port 11, so traffic always go to the dedicated link (direct fibers), and than with all working i just decide to pull the fiber on port 15 on active Firepower on Site A to simulate a fail on LACP (Etherchannel) to see how long Cisco Firepower takes to switch to port 16, and the result is Firepower switch back to Port 11 (IT network) and when i connect back the port 15 (dedicated fiber) the Firepower cant estabilish back the etherchannel, i have to delete the etherchannel and create a new etherchannel to make the dedicated link work again, in my opinion the time the Firepower takes to switch interface on etherchannel is bigger than the time the OSPF choose to change to port 11, and i dont have any clue why the etherchannel cant restabilish connection, dont even know if im doing something wrong, the physical connection is showed on figure bellow

TOPOLOGY.png

1 Reply 1

this design can not work 
you need SW connect to Inside and Outside of FW 
you can not connect FW back to back 

MHM

Review Cisco Networking for a $25 gift card